GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,744
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,605 advisories
Filter by severity
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6,...
High
Unreviewed
CVE-2025-12029
was published
Dec 11, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18...
High
Unreviewed
CVE-2025-12716
was published
Dec 11, 2025
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft...
High
Unreviewed
CVE-2025-64672
was published
Dec 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-67541
was published
Dec 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-63057
was published
Dec 9, 2025
An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick...
High
Unreviewed
CVE-2025-41749
was published
Dec 9, 2025
An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41751
was published
Dec 9, 2025
An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41747
was published
Dec 9, 2025
An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41745
was published
Dec 9, 2025
An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick...
High
Unreviewed
CVE-2025-41695
was published
Dec 9, 2025
An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41752
was published
Dec 9, 2025
An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41748
was published
Dec 9, 2025
An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41746
was published
Dec 9, 2025
An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to...
High
Unreviewed
CVE-2025-41750
was published
Dec 9, 2025
The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-13604
was published
Dec 9, 2025
The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2025-12705
was published
Dec 9, 2025
In affected versions, vulnerability-lookup handled user-controlled
content in comments and...
High
Unreviewed
CVE-2025-42620
was published
Dec 8, 2025
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry...
High
Unreviewed
CVE-2025-12956
was published
Dec 8, 2025
The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2025-12499
was published
Dec 6, 2025
The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
High
Unreviewed
CVE-2025-12510
was published
Dec 6, 2025
The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
High
Unreviewed
CVE-2025-13614
was published
Dec 5, 2025
The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto...
High
Unreviewed
CVE-2025-11727
was published
Dec 4, 2025
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote...
High
Unreviewed
CVE-2025-13639
was published
Dec 2, 2025
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2025-13387
was published
Dec 2, 2025
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within...
High
Unreviewed
CVE-2025-63534
was published
Dec 1, 2025
ProTip!
Advisories are also available from the
GraphQL API