GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
301,774 advisories
Filter by severity
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
High
Unreviewed
CVE-2025-58320
was published
Sep 11, 2025
The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-9855
was published
Sep 11, 2025
The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
Moderate
Unreviewed
CVE-2025-9633
was published
Sep 11, 2025
The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-9635
was published
Sep 11, 2025
The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-9861
was published
Sep 11, 2025
The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-9850
was published
Sep 11, 2025
The User Meta – User Profile Builder and User management plugin plugin for WordPress is...
High
Unreviewed
CVE-2025-9693
was published
Sep 11, 2025
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
Critical
Unreviewed
CVE-2025-58321
was published
Sep 11, 2025
The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in...
High
Unreviewed
CVE-2025-9874
was published
Sep 11, 2025
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to...
Critical
Unreviewed
CVE-2025-8570
was published
Sep 11, 2025
The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-9123
was published
Sep 11, 2025
The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8215
was published
Sep 11, 2025
The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’...
Moderate
Unreviewed
CVE-2025-8318
was published
Sep 11, 2025
The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’...
Moderate
Unreviewed
CVE-2025-8692
was published
Sep 11, 2025
The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2025-9628
was published
Sep 11, 2025
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection...
High
Unreviewed
CVE-2025-8417
was published
Sep 11, 2025
The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-8481
was published
Sep 11, 2025
The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id'...
High
Unreviewed
CVE-2025-9073
was published
Sep 11, 2025
The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8445
was published
Sep 11, 2025
The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-9617
was published
Sep 11, 2025
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for...
Moderate
Unreviewed
CVE-2025-8492
was published
Sep 11, 2025
The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
Moderate
Unreviewed
CVE-2025-9631
was published
Sep 11, 2025
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due...
Moderate
Unreviewed
CVE-2025-8423
was published
Sep 11, 2025
The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
Moderate
Unreviewed
CVE-2025-9620
was published
Sep 11, 2025
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-8422
was published
Sep 11, 2025
ProTip!
Advisories are also available from the
GraphQL API