GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,003 advisories
Filter by severity
The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in...
Critical
Unreviewed
CVE-2025-13615
was published
Nov 30, 2025
WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated...
High
Unreviewed
CVE-2025-13768
was published
Nov 28, 2025
The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2025-13157
was published
Nov 27, 2025
Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and...
High
Unreviewed
CVE-2025-65672
was published
Nov 26, 2025
An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access...
Moderate
Unreviewed
CVE-2025-65670
was published
Nov 26, 2025
Better Auth Passkey Plugin allows passkey deletion through IDOR
High
GHSA-4vcf-q4xf-f48m
was published
for
@better-auth/passkey
(npm)
Nov 25, 2025
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping...
Moderate
Unreviewed
CVE-2025-65647
was published
Nov 25, 2025
Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered...
Moderate
Unreviewed
CVE-2025-64067
was published
Nov 25, 2025
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-13389
was published
Nov 25, 2025
The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference...
Moderate
Unreviewed
CVE-2025-13382
was published
Nov 25, 2025
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-13452
was published
Nov 25, 2025
The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2025-12040
was published
Nov 25, 2025
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-10039
was published
Nov 21, 2025
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2025-12881
was published
Nov 21, 2025
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2025-12086
was published
Nov 21, 2025
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry®...
Moderate
Unreviewed
CVE-2025-12766
was published
Nov 19, 2025
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2025-12427
was published
Nov 19, 2025
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR)...
Moderate
Unreviewed
CVE-2025-63513
was published
Nov 18, 2025
Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This...
Moderate
Unreviewed
CVE-2025-41069
was published
Nov 13, 2025
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-12366
was published
Nov 13, 2025
The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization...
High
Unreviewed
CVE-2025-12903
was published
Nov 12, 2025
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for...
Moderate
Unreviewed
CVE-2025-12833
was published
Nov 12, 2025
The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2025-12087
was published
Nov 12, 2025
The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference...
Moderate
Unreviewed
CVE-2025-12126
was published
Nov 11, 2025
ProTip!
Advisories are also available from the
GraphQL API