GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,874
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,163
NuGet
741
pip
3,961
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
635 advisories
Filter by severity
Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del...
Moderate
Unreviewed
CVE-2025-40678
was published
Sep 18, 2025
A weakness has been identified in SourceCodester Online Student File Management System 1.0. This...
Moderate
Unreviewed
CVE-2025-10480
was published
Sep 16, 2025
The rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series ...
Moderate
Unreviewed
CVE-2025-57176
was published
Sep 15, 2025
A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This...
Moderate
Unreviewed
CVE-2025-10427
was published
Sep 15, 2025
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0...
Moderate
Unreviewed
CVE-2025-10428
was published
Sep 15, 2025
A vulnerability was determined in 1000projects Online Student Project Report Submission and...
Moderate
Unreviewed
CVE-2025-10424
was published
Sep 15, 2025
A vulnerability was identified in 1000projects Online Student Project Report Submission and...
Moderate
Unreviewed
CVE-2025-10425
was published
Sep 15, 2025
A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is...
Moderate
Unreviewed
CVE-2025-9847
was published
Sep 10, 2025
A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This...
Moderate
Unreviewed
CVE-2025-10085
was published
Sep 8, 2025
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected...
Moderate
Unreviewed
CVE-2025-10083
was published
Sep 8, 2025
A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-10081
was published
Sep 8, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the...
Moderate
Unreviewed
CVE-2025-31979
was published
Aug 28, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient...
Moderate
Unreviewed
CVE-2024-9648
was published
Aug 28, 2025
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function...
Moderate
Unreviewed
CVE-2025-9406
was published
Aug 25, 2025
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of...
Moderate
Unreviewed
CVE-2025-9397
was published
Aug 25, 2025
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via a specific service...
Moderate
Unreviewed
CVE-2025-24489
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via the a specific...
Moderate
Unreviewed
CVE-2025-27714
was published
Aug 21, 2025
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9296
was published
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API