GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
240 advisories
Filter by severity
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify...
Critical
Unreviewed
CVE-2025-33117
was published
Jun 19, 2025
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
High
Unreviewed
CVE-2025-6463
was published
Jul 2, 2025
External control of file name or path in Windows Storage allows an authorized attacker to perform...
Low
Unreviewed
CVE-2025-49760
was published
Jul 8, 2025
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-6691
was published
Jul 9, 2025
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-5393
was published
Jul 15, 2025
The go command may execute unexpected commands when operating in untrusted VCS repositories. This...
High
Unreviewed
CVE-2025-4674
was published
Jul 30, 2025
: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows :...
High
Unreviewed
CVE-2025-29866
was published
Aug 7, 2025
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-53769
was published
Aug 12, 2025
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows...
High
Unreviewed
CVE-2011-10030
was published
Aug 20, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20269
was published
Aug 20, 2025
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
Critical
CVE-2025-55746
was published
for
@directus/api
(npm)
Aug 20, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-9048
was published
Aug 23, 2025
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element...
Moderate
Unreviewed
CVE-2025-9529
was published
Aug 27, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous...
Low
Unreviewed
CVE-2025-10043
was published
Sep 5, 2025
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2025-10134
was published
Sep 9, 2025
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts...
Moderate
Unreviewed
CVE-2025-9920
was published
Sep 9, 2025
External control of file name or path in Azure Arc allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-55316
was published
Sep 9, 2025
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-8422
was published
Sep 11, 2025
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-10058
was published
Sep 17, 2025
InvokeAI has External Control of File Name or Path
Critical
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
An external control of file name or path vulnerability in SUNNET Corporate Training Management...
Critical
Unreviewed
CVE-2025-54945
was published
Sep 25, 2025
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup...
Low
Unreviewed
CVE-2025-10306
was published
Oct 3, 2025
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-10494
was published
Oct 8, 2025
ProTip!
Advisories are also available from the
GraphQL API