GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
820 advisories
Filter by severity
A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of...
Moderate
Unreviewed
CVE-2025-14008
was published
Dec 4, 2025
A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-14004
was published
Dec 4, 2025
Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host
Moderate
CVE-2025-66405
was published
for
@portkey-ai/gateway
(npm)
Dec 2, 2025
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary...
Moderate
Unreviewed
CVE-2025-27232
was published
Dec 1, 2025
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the...
Moderate
Unreviewed
CVE-2025-13814
was published
Dec 1, 2025
A vulnerability has been found in orionsec orion-ops up to...
Moderate
Unreviewed
CVE-2025-13809
was published
Dec 1, 2025
A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this...
Moderate
Unreviewed
CVE-2025-13796
was published
Dec 1, 2025
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of...
Moderate
Unreviewed
CVE-2025-13789
was published
Nov 30, 2025
The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-13378
was published
Nov 27, 2025
A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted...
Moderate
Unreviewed
CVE-2025-13588
was published
Nov 24, 2025
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side...
Moderate
Unreviewed
CVE-2025-12800
was published
Nov 24, 2025
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects...
Moderate
Unreviewed
CVE-2025-13147
was published
Nov 19, 2025
The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request...
Moderate
Unreviewed
CVE-2025-12359
was published
Nov 19, 2025
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
Moderate
Unreviewed
CVE-2025-8084
was published
Nov 18, 2025
The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-12376
was published
Nov 18, 2025
The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind...
Moderate
Unreviewed
CVE-2025-11427
was published
Nov 18, 2025
The Local Syndication plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
Moderate
Unreviewed
CVE-2025-12962
was published
Nov 18, 2025
A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This...
Moderate
Unreviewed
CVE-2025-9805
was published
Nov 14, 2025
A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this...
Moderate
Unreviewed
CVE-2025-13174
was published
Nov 14, 2025
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Moderate
CVE-2025-64525
was published
for
astro
(npm)
Nov 13, 2025
Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a...
Moderate
Unreviewed
CVE-2025-52186
was published
Nov 13, 2025
Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates...
Moderate
Unreviewed
CVE-2025-62988
was published
Oct 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows...
Moderate
Unreviewed
CVE-2025-49374
was published
Oct 22, 2025
Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers...
Moderate
Unreviewed
CVE-2025-49917
was published
Oct 22, 2025
OpenShift Console Server Side Request Forgery vulnerability
Moderate
CVE-2024-6538
was published
for
github.com/openshift/console
(Go)
Nov 25, 2024
ProTip!
Advisories are also available from the
GraphQL API