GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,047 advisories
Filter by severity
The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
Critical
Unreviewed
CVE-2025-6679
was published
Aug 15, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block allows Upload...
Critical
Unreviewed
CVE-2025-54693
was published
Aug 14, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a...
Critical
Unreviewed
CVE-2025-24775
was published
Aug 14, 2025
PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its...
High
Unreviewed
CVE-2012-10056
was published
Aug 13, 2025
Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via...
Critical
Unreviewed
CVE-2012-10054
was published
Aug 13, 2025
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a...
High
Unreviewed
CVE-2025-8297
was published
Aug 12, 2025
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX...
Moderate
Unreviewed
CVE-2025-33023
was published
Aug 12, 2025
Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in...
Critical
Unreviewed
CVE-2012-10038
was published
Aug 11, 2025
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this...
Moderate
Unreviewed
CVE-2025-8841
was published
Aug 11, 2025
A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as...
Moderate
Unreviewed
CVE-2025-8775
was published
Aug 9, 2025
EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the...
Critical
Unreviewed
CVE-2012-10052
was published
Aug 8, 2025
XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote...
Critical
Unreviewed
CVE-2012-10045
was published
Aug 8, 2025
CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the...
Critical
Unreviewed
CVE-2012-10050
was published
Aug 8, 2025
WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the...
Critical
Unreviewed
CVE-2012-10049
was published
Aug 8, 2025
Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog...
High
Unreviewed
CVE-2012-10042
was published
Aug 8, 2025
Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in...
Critical
Unreviewed
CVE-2012-10036
was published
Aug 8, 2025
MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php...
Critical
Unreviewed
CVE-2012-10044
was published
Aug 8, 2025
In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to...
Moderate
Unreviewed
CVE-2025-55135
was published
Aug 7, 2025
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote...
High
Unreviewed
CVE-2025-51056
was published
Aug 6, 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to...
High
Unreviewed
CVE-2025-50286
was published
Aug 6, 2025
CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow...
Critical
Unreviewed
CVE-2025-22470
was published
Aug 6, 2025
WP-Property plugin for WordPress through version 1.35.0 contains an unauthenticated file upload...
Critical
Unreviewed
CVE-2012-10027
was published
Aug 5, 2025
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary...
Critical
Unreviewed
CVE-2012-10026
was published
Aug 5, 2025
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload...
Critical
Unreviewed
CVE-2013-10067
was published
Aug 5, 2025
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The...
Critical
Unreviewed
CVE-2013-10066
was published
Aug 5, 2025
ProTip!
Advisories are also available from the
GraphQL API