GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,768 advisories
Filter by severity
The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-4222
was published
May 3, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in...
Moderate
Unreviewed
CVE-2025-2880
was published
May 2, 2025
APM server logs could contain parts of the document body from a partially failed bulk index...
Moderate
Unreviewed
CVE-2024-11994
was published
May 1, 2025
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic...
Moderate
Unreviewed
CVE-2023-46669
was published
May 1, 2025
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15...
Moderate
Unreviewed
CVE-2025-24270
was published
Apr 29, 2025
A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by...
Moderate
Unreviewed
CVE-2025-3978
was published
Apr 27, 2025
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as...
Moderate
Unreviewed
CVE-2025-3975
was published
Apr 27, 2025
A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by...
Moderate
Unreviewed
CVE-2025-3966
was published
Apr 27, 2025
Moodle reveals student identities through assignment submissions search on anonymous submissions
Moderate
CVE-2025-3628
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-3923
was published
Apr 25, 2025
The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2024-11299
was published
Apr 22, 2025
An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a...
Moderate
Unreviewed
CVE-2025-29316
was published
Apr 17, 2025
The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in...
Moderate
Unreviewed
CVE-2025-3104
was published
Apr 16, 2025
Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. ...
Moderate
Unreviewed
CVE-2025-30702
was published
Apr 15, 2025
cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
Moderate
Unreviewed
CVE-2025-27980
was published
Apr 15, 2025
The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-2881
was published
Apr 12, 2025
The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-2841
was published
Apr 12, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia...
Moderate
Unreviewed
CVE-2025-32080
was published
Apr 11, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface...
Moderate
Unreviewed
CVE-2025-30654
was published
Apr 9, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure...
Moderate
Unreviewed
CVE-2025-30291
was published
Apr 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency...
Moderate
Unreviewed
CVE-2025-27736
was published
Apr 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access...
Moderate
Unreviewed
CVE-2025-26667
was published
Apr 8, 2025
The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2025-2883
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API