GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,047 advisories
Filter by severity
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function...
Moderate
Unreviewed
CVE-2025-9406
was published
Aug 25, 2025
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of...
Moderate
Unreviewed
CVE-2025-9397
was published
Aug 25, 2025
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to...
High
Unreviewed
CVE-2025-36174
was published
Aug 24, 2025
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26497
was published
Aug 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26498
was published
Aug 22, 2025
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask...
High
Unreviewed
CVE-2025-55454
was published
Aug 22, 2025
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via...
Low
Unreviewed
CVE-2025-55455
was published
Aug 22, 2025
The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to...
High
Unreviewed
CVE-2025-54460
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via a specific service...
Moderate
Unreviewed
CVE-2025-24489
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via the a specific...
Moderate
Unreviewed
CVE-2025-27714
was published
Aug 21, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a...
Critical
Unreviewed
CVE-2025-53251
was published
Aug 21, 2025
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows...
High
Unreviewed
CVE-2025-55383
was published
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
CVE-2025-55743
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9296
was published
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
A weakness has been identified in Emlog Pro up to 2.5.18. This issue affects some unknown...
Moderate
Unreviewed
CVE-2025-9173
was published
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking &...
Critical
Unreviewed
CVE-2025-54677
was published
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip...
Critical
Unreviewed
CVE-2025-53213
was published
Aug 20, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for...
Critical
Unreviewed
CVE-2025-48148
was published
Aug 20, 2025
MoonShine Arbitrary File Upload Vulnerability
Moderate
CVE-2025-51489
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to...
Critical
Unreviewed
CVE-2025-7441
was published
Aug 16, 2025
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2025-6079
was published
Aug 16, 2025
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for...
Critical
Unreviewed
CVE-2025-54473
was published
Aug 15, 2025
ProTip!
Advisories are also available from the
GraphQL API