GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,142 advisories
Filter by severity
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve...
Moderate
Unreviewed
CVE-2025-34521
was published
Aug 28, 2025
A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-9665
was published
Aug 29, 2025
A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue...
Moderate
Unreviewed
CVE-2025-9610
was published
Aug 29, 2025
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents...
Moderate
Unreviewed
CVE-2024-55955
was published
Dec 31, 2024
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
Milestone Systems has discovered a
security vulnerability in Milestone XProtect installer that...
Moderate
Unreviewed
CVE-2025-1688
was published
Apr 15, 2025
A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS...
Moderate
Unreviewed
CVE-2025-40594
was published
Sep 9, 2025
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC...
Moderate
Unreviewed
CVE-2025-40757
was published
Sep 9, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in...
Moderate
Unreviewed
CVE-2025-9542
was published
Sep 9, 2025
The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes...
Moderate
Unreviewed
CVE-2025-9058
was published
Sep 9, 2025
The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes...
Moderate
Unreviewed
CVE-2025-9061
was published
Sep 9, 2025
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2025-9489
was published
Sep 9, 2025
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an...
Moderate
Unreviewed
CVE-2025-42920
was published
Sep 9, 2025
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker...
Moderate
Unreviewed
CVE-2025-42926
was published
Sep 9, 2025
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an...
Moderate
Unreviewed
CVE-2025-42938
was published
Sep 9, 2025
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background...
Moderate
Unreviewed
CVE-2025-42918
was published
Sep 9, 2025
Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an...
Moderate
Unreviewed
CVE-2025-42915
was published
Sep 9, 2025
Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated...
Moderate
Unreviewed
CVE-2025-42923
was published
Sep 9, 2025
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled...
Moderate
Unreviewed
CVE-2025-42911
was published
Sep 9, 2025
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP...
Moderate
Unreviewed
CVE-2025-42925
was published
Sep 9, 2025
SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks...
Moderate
Unreviewed
CVE-2025-42917
was published
Sep 9, 2025
SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an...
Moderate
Unreviewed
CVE-2025-42912
was published
Sep 9, 2025
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file...
Moderate
Unreviewed
CVE-2025-10122
was published
Sep 9, 2025
A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code...
Moderate
Unreviewed
CVE-2025-10116
was published
Sep 9, 2025
SAP Business Planning and Consolidation allows an authenticated standard user to call a function...
Moderate
Unreviewed
CVE-2025-42930
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API