GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
415 advisories
Filter by severity
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-23937
was published
Mar 26, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-23952
was published
Mar 26, 2025
The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
High
Unreviewed
CVE-2024-12563
was published
Mar 18, 2025
Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=....
High
Unreviewed
CVE-2025-26137
was published
Mar 18, 2025
The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up...
High
Unreviewed
CVE-2025-1707
was published
Mar 12, 2025
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows...
High
Unreviewed
CVE-2024-51319
was published
Mar 11, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26933
was published
Mar 10, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-27264
was published
Mar 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-25109
was published
Mar 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-23945
was published
Mar 3, 2025
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
High
Unreviewed
CVE-2024-12811
was published
Feb 28, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26979
was published
Feb 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26985
was published
Feb 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26964
was published
Feb 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26957
was published
Feb 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26932
was published
Feb 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-27272
was published
Feb 24, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26760
was published
Feb 22, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26757
was published
Feb 22, 2025
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin...
High
Unreviewed
CVE-2024-13353
was published
Feb 21, 2025
The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is...
High
Unreviewed
CVE-2024-13592
was published
Feb 19, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-22656
was published
Feb 18, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-25141
was published
Feb 7, 2025
The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all...
High
Unreviewed
CVE-2024-12859
was published
Feb 3, 2025
The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code...
High
Unreviewed
CVE-2025-0366
was published
Feb 1, 2025
ProTip!
Advisories are also available from the
GraphQL API