GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,933
Erlang
39
GitHub Actions
38
Go
2,595
Maven
5,000+
npm
4,247
NuGet
754
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
129,794 advisories
Filter by severity
Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a...
Moderate
Unreviewed
CVE-2025-41402
was published
Oct 23, 2025
Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of...
Moderate
Unreviewed
CVE-2025-62499
was published
Oct 23, 2025
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre...
Moderate
Unreviewed
CVE-2025-35981
was published
Oct 23, 2025
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could...
Moderate
Unreviewed
CVE-2025-48428
was published
Oct 23, 2025
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary...
Moderate
Unreviewed
CVE-2025-62820
was published
Oct 23, 2025
GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert...
Moderate
Unreviewed
CVE-2025-54806
was published
Oct 23, 2025
Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If...
Moderate
Unreviewed
CVE-2025-54856
was published
Oct 23, 2025
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly...
Moderate
Unreviewed
CVE-2025-62813
was published
Oct 23, 2025
Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged...
Moderate
Unreviewed
CVE-2025-48430
was published
Oct 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-60135
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in BoldThemes Addison addison allows Object...
Moderate
Unreviewed
CVE-2025-60216
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-60176
was published
Oct 22, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-60217
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpshuffle Subscribe to Download subscribe-to...
Moderate
Unreviewed
CVE-2025-60224
was published
Oct 22, 2025
Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin ...
Moderate
Unreviewed
CVE-2025-60211
was published
Oct 22, 2025
Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce...
Moderate
Unreviewed
CVE-2025-60222
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in captivateaudio Captivate Sync captivatesync...
Moderate
Unreviewed
CVE-2025-60221
was published
Oct 22, 2025
Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing...
Moderate
Unreviewed
CVE-2025-49906
was published
Oct 22, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-48338
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49908
was published
Oct 22, 2025
Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows...
Moderate
Unreviewed
CVE-2025-49374
was published
Oct 22, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT...
Moderate
Unreviewed
CVE-2025-60208
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder...
Moderate
Unreviewed
CVE-2025-49380
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object...
Moderate
Unreviewed
CVE-2025-60215
was published
Oct 22, 2025
Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing...
Moderate
Unreviewed
CVE-2025-60210
was published
Oct 22, 2025
ProTip!
Advisories are also available from the
GraphQL API