GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,047 advisories
Filter by severity
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to...
Critical
Unreviewed
CVE-2025-7441
was published
Aug 16, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking &...
Critical
Unreviewed
CVE-2025-54677
was published
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for...
Critical
Unreviewed
CVE-2025-48148
was published
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip...
Critical
Unreviewed
CVE-2025-53213
was published
Aug 20, 2025
Matrix Media Repo (MMR) allows untrusted file formats can be thumbnailed, invoking potentially further untrusted decoders
Moderate
CVE-2024-56515
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a...
Critical
Unreviewed
CVE-2025-53251
was published
Aug 21, 2025
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows...
High
Unreviewed
CVE-2025-55383
was published
Aug 21, 2025
MoonShine Arbitrary File Upload Vulnerability
Moderate
CVE-2025-51489
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This...
Moderate
Unreviewed
CVE-2024-13022
was published
Dec 29, 2024
NocoDB Allows Preview of Files with Dangerous Content
Moderate
CVE-2023-50717
was published
for
nocodb
(npm)
May 13, 2024
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
CVE-2025-55743
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to...
High
Unreviewed
CVE-2025-54460
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via a specific service...
Moderate
Unreviewed
CVE-2025-24489
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via the a specific...
Moderate
Unreviewed
CVE-2025-27714
was published
Aug 21, 2025
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This...
Moderate
Unreviewed
CVE-2024-13201
was published
Jan 9, 2025
A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2024-13210
was published
Jan 9, 2025
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the...
Moderate
Unreviewed
CVE-2024-13144
was published
Jan 6, 2025
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this...
Moderate
Unreviewed
CVE-2024-13145
was published
Jan 6, 2025
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to...
High
Unreviewed
CVE-2025-36174
was published
Aug 24, 2025
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26497
was published
Aug 22, 2025
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via...
Low
Unreviewed
CVE-2025-55455
was published
Aug 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26498
was published
Aug 22, 2025
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious...
High
Unreviewed
CVE-2025-53119
was published
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API