GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
301,203 advisories
Filter by severity
ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write...
Moderate
Unreviewed
CVE-2025-55824
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58880
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product allows...
Moderate
Unreviewed
CVE-2025-58878
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58882
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58876
was published
Sep 5, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58881
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58887
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58884
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-8695
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58883
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58886
was published
Sep 5, 2025
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request.
High
Unreviewed
CVE-2025-58780
was published
Sep 5, 2025
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted...
Moderate
Unreviewed
CVE-2025-10012
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS....
High
Unreviewed
CVE-2025-58847
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored...
High
Unreviewed
CVE-2025-58861
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58870
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58834
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58863
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in reimund Compact Admin allows Cross Site...
Moderate
Unreviewed
CVE-2025-58865
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58864
was published
Sep 5, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami...
Low
Unreviewed
CVE-2025-58866
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58871
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58873
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes allows Reflected XSS. This...
High
Unreviewed
CVE-2025-58848
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58874
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API