GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
305,616 advisories
Filter by severity
A vulnerability was determined in code-projects Student File Management System 1.0. Affected by...
Moderate
Unreviewed
CVE-2025-14620
was published
Dec 13, 2025
A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this...
Low
Unreviewed
CVE-2025-14606
was published
Dec 13, 2025
A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function...
Moderate
Unreviewed
CVE-2025-14607
was published
Dec 13, 2025
The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-7960
was published
Dec 13, 2025
The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
Moderate
Unreviewed
CVE-2025-8687
was published
Dec 13, 2025
The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-9488
was published
Dec 13, 2025
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-8195
was published
Dec 13, 2025
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X....
Critical
Unreviewed
CVE-2025-36751
was published
Dec 13, 2025
Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented...
Critical
Unreviewed
CVE-2025-36752
was published
Dec 13, 2025
The SWD debug interface on the Growatt ShineLan-X communication dongle is available by default,...
High
Unreviewed
CVE-2025-36753
was published
Dec 13, 2025
The authentication mechanism on web interface is not properly implemented. It is possible to...
Critical
Unreviewed
CVE-2025-36754
was published
Dec 13, 2025
The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-7058
was published
Dec 13, 2025
A security flaw has been discovered in itsourcecode Student Management System 1.0. This...
Moderate
Unreviewed
CVE-2025-14588
was published
Dec 13, 2025
A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This...
Moderate
Unreviewed
CVE-2025-14587
was published
Dec 13, 2025
The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-14508
was published
Dec 13, 2025
The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization...
Moderate
Unreviewed
CVE-2025-14581
was published
Dec 13, 2025
The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
Moderate
Unreviewed
CVE-2025-14539
was published
Dec 13, 2025
ProTip!
Advisories are also available from the
GraphQL API