GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,583 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path allows Stored...
High
Unreviewed
CVE-2025-58849
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex allows Stored XSS....
High
Unreviewed
CVE-2025-58860
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in ChrisHurst Bulk Watermark allows Reflected XSS...
High
Unreviewed
CVE-2025-58845
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro allows Reflected XSS....
High
Unreviewed
CVE-2025-58847
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager allows...
High
Unreviewed
CVE-2025-58852
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login allows...
High
Unreviewed
CVE-2025-58854
was published
Sep 5, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58881
was published
Sep 5, 2025
Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon allows Object...
High
Unreviewed
CVE-2025-58815
was published
Sep 5, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58788
was published
Sep 5, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58789
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in imjoehaines WordPress Error Monitoring by...
High
Unreviewed
CVE-2025-58806
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce allows...
High
Unreviewed
CVE-2025-58809
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache allows Stored XSS....
High
Unreviewed
CVE-2025-58807
was published
Sep 5, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored...
High
Unreviewed
CVE-2025-58861
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-58857
was published
Sep 5, 2025
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-3509
was published
Apr 18, 2025
Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy...
High
Unreviewed
CVE-2025-1860
was published
Mar 28, 2025
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
Hexo `include_code` has a path traversal
High
CVE-2023-39584
was published
for
hexo
(npm)
Sep 8, 2023
Out-of-bounds read vulnerability in the runtime interpreter module.
Impact: Successful...
High
Unreviewed
CVE-2025-58281
was published
Sep 5, 2025
Race condition vulnerability in the audio module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2025-58296
was published
Sep 5, 2025
Vulnerability of exposing object heap addresses in the Ark eTS module.
Impact: Successful...
High
Unreviewed
CVE-2025-58280
was published
Sep 5, 2025
The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which...
High
Unreviewed
CVE-2025-2190
was published
Mar 11, 2025
Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to ...
High
Unreviewed
CVE-2025-3698
was published
Apr 16, 2025
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user...
High
Unreviewed
CVE-2024-7697
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API