GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,858 advisories
Filter by severity
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for...
Critical
Unreviewed
CVE-2025-48148
was published
Aug 20, 2025
Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack...
Critical
Unreviewed
CVE-2024-12223
was published
Aug 20, 2025
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence...
Critical
Unreviewed
CVE-2025-9187
was published
Aug 19, 2025
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid...
Critical
Unreviewed
CVE-2025-55031
was published
Aug 19, 2025
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start...
Critical
Unreviewed
CVE-2025-8042
was published
Aug 19, 2025
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the...
Critical
Unreviewed
CVE-2025-54143
was published
Aug 19, 2025
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a...
Critical
Unreviewed
CVE-2025-54145
was published
Aug 19, 2025
An attacker was able to perform memory corruption in the GMP process which processes encrypted...
Critical
Unreviewed
CVE-2025-9179
was published
Aug 19, 2025
A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to...
Critical
Unreviewed
CVE-2024-44373
was published
Aug 19, 2025
screenshot-desktop vulnerable to command Injection via `format` option
Critical
CVE-2025-55294
was published
for
screenshot-desktop
(npm)
Aug 19, 2025
HydrAIDE Authentication Bypass Vulnerability
Critical
GHSA-qp7j-x725-g67f
was published
for
github.com/hydraide/hydraide
(Go)
Aug 19, 2025
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function,...
Critical
Unreviewed
CVE-2025-50567
was published
Aug 19, 2025
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct...
Critical
Unreviewed
CVE-2025-54336
was published
Aug 19, 2025
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-6758
was published
Aug 19, 2025
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to...
Critical
Unreviewed
CVE-2025-8723
was published
Aug 19, 2025
The Sante PACS Server Web Portal sends credential information without encryption.
Critical
Unreviewed
CVE-2025-54156
was published
Aug 19, 2025
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-55591
was published
Aug 18, 2025
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Critical
CVE-2025-55205
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 18, 2025
A security issue exists due to improper handling of malformed CIP Forward Close packets during...
Critical
Unreviewed
CVE-2025-7693
was published
Aug 18, 2025
In vowifi service, there is a possible command injection due to improper input validation. This...
Critical
Unreviewed
CVE-2025-31715
was published
Aug 18, 2025
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2025-8898
was published
Aug 16, 2025
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to...
Critical
Unreviewed
CVE-2025-7441
was published
Aug 16, 2025
A vulnerability has been found in the MSoft MFlash
application that allows
execution of...
Critical
Unreviewed
CVE-2025-9060
was published
Aug 15, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator...
Critical
Unreviewed
CVE-2025-8995
was published
Aug 15, 2025
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for...
Critical
Unreviewed
CVE-2025-54473
was published
Aug 15, 2025
ProTip!
Advisories are also available from the
GraphQL API