GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,522
Maven
5,000+
npm
4,176
NuGet
741
pip
3,965
Pub
12
RubyGems
947
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,048 advisories
Filter by severity
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an...
Critical
Unreviewed
CVE-2021-4457
was published
Jun 26, 2025
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project...
Moderate
Unreviewed
CVE-2025-27127
was published
Jul 8, 2025
A vulnerability classified as critical has been found in Project Worlds Online Time Table...
Moderate
Unreviewed
CVE-2025-3041
was published
Apr 1, 2025
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1...
Moderate
Unreviewed
CVE-2025-3042
was published
Apr 1, 2025
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2025-3040
was published
Apr 1, 2025
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2024-8856
was published
Nov 16, 2024
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-6843
was published
Jun 29, 2025
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by...
Moderate
Unreviewed
CVE-2024-39752
was published
Jul 10, 2025
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to...
High
Unreviewed
CVE-2025-34097
was published
Jul 10, 2025
A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-6667
was published
Jun 26, 2025
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file...
High
Unreviewed
CVE-2025-6057
was published
Jul 12, 2025
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file...
Critical
Unreviewed
CVE-2025-6058
was published
Jul 12, 2025
The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to...
High
Unreviewed
CVE-2025-6423
was published
Jul 12, 2025
The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2020-36849
was published
Jul 12, 2025
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up...
Critical
Unreviewed
CVE-2020-36847
was published
Jul 12, 2025
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `...
Critical
Unreviewed
CVE-2024-2221
was published
Apr 10, 2024
If a user saved a response from the Network tab in Devtools using the Save As context menu option...
High
Unreviewed
CVE-2025-6435
was published
Jun 26, 2025
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin...
Critical
Unreviewed
CVE-2025-7340
was published
Jul 15, 2025
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-7470
was published
Jul 12, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg allows...
Critical
Unreviewed
CVE-2025-48300
was published
Jul 16, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription...
Critical
Unreviewed
CVE-2025-29009
was published
Jul 16, 2025
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could...
Moderate
Unreviewed
CVE-2025-20274
was published
Jul 16, 2025
File upload vulnerability in Instantdeveloper RD3 22.0.8500, allows attackers to execute...
Critical
Unreviewed
CVE-2022-39983
was published
Feb 23, 2023
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User...
Critical
Unreviewed
CVE-2025-6222
was published
Jul 18, 2025
ProTip!
Advisories are also available from the
GraphQL API