GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,019
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,859 advisories
Filter by severity
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to...
Critical
Unreviewed
CVE-2025-8723
was published
Aug 19, 2025
The Sante PACS Server Web Portal sends credential information without encryption.
Critical
Unreviewed
CVE-2025-54156
was published
Aug 19, 2025
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-55591
was published
Aug 18, 2025
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its...
Critical
Unreviewed
CVE-2011-10019
was published
Aug 13, 2025
Flowise OS command remote code execution
Critical
CVE-2025-8943
was published
for
flowise
(npm)
Aug 14, 2025
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22941
was published
Mar 31, 2025
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to...
Critical
Unreviewed
CVE-2025-8356
was published
Aug 8, 2025
A security issue exists due to improper handling of malformed CIP Forward Close packets during...
Critical
Unreviewed
CVE-2025-7693
was published
Aug 18, 2025
Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to...
Critical
Unreviewed
CVE-2025-22940
was published
Mar 31, 2025
A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows...
Critical
Unreviewed
CVE-2025-22939
was published
Mar 31, 2025
An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via...
Critical
Unreviewed
CVE-2025-22937
was published
Mar 31, 2025
Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.
Critical
Unreviewed
CVE-2025-22938
was published
Mar 31, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
In vowifi service, there is a possible command injection due to improper input validation. This...
Critical
Unreviewed
CVE-2025-31715
was published
Aug 18, 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to...
Critical
Unreviewed
CVE-2025-23266
was published
Jul 17, 2025
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2025-8898
was published
Aug 16, 2025
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to...
Critical
Unreviewed
CVE-2025-7441
was published
Aug 16, 2025
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center...
Critical
Unreviewed
CVE-2025-20265
was published
Aug 14, 2025
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
Critical
Unreviewed
CVE-2021-30194
was published
May 24, 2022
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
Critical
Unreviewed
CVE-2021-30189
was published
May 24, 2022
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
Critical
Unreviewed
CVE-2021-30188
was published
May 24, 2022
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
Critical
Unreviewed
CVE-2021-30193
was published
May 24, 2022
A vulnerability has been found in the MSoft MFlash
application that allows
execution of...
Critical
Unreviewed
CVE-2025-9060
was published
Aug 15, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
Critical
Unreviewed
CVE-2025-25256
was published
Aug 12, 2025
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control...
Critical
Unreviewed
CVE-2025-43983
was published
Aug 14, 2025
ProTip!
Advisories are also available from the
GraphQL API