GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,029 advisories
Filter by severity
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the...
Moderate
Unreviewed
CVE-2025-31979
was published
Aug 28, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File...
Critical
Unreviewed
CVE-2025-49387
was published
Aug 28, 2025
SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated...
Critical
Unreviewed
CVE-2025-53970
was published
Aug 28, 2025
SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated...
Critical
Unreviewed
CVE-2025-54762
was published
Aug 28, 2025
The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient...
Moderate
Unreviewed
CVE-2024-9648
was published
Aug 28, 2025
Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile...
Critical
Unreviewed
CVE-2025-34163
was published
Aug 28, 2025
Badaso CMS file upload vulnerability
High
CVE-2025-52353
was published
for
badaso/core
(Composer)
Aug 26, 2025
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious...
High
Unreviewed
CVE-2025-53119
was published
Aug 26, 2025
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function...
Moderate
Unreviewed
CVE-2025-9406
was published
Aug 25, 2025
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of...
Moderate
Unreviewed
CVE-2025-9397
was published
Aug 25, 2025
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to...
High
Unreviewed
CVE-2025-36174
was published
Aug 24, 2025
Liferay Portal allows unrestricted upload of file in the style books component
Moderate
CVE-2025-43766
was published
for
com.liferay:com.liferay.style.book.web
(Maven)
Aug 23, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26498
was published
Aug 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on...
High
Unreviewed
CVE-2025-26497
was published
Aug 22, 2025
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via...
Low
Unreviewed
CVE-2025-55455
was published
Aug 22, 2025
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask...
High
Unreviewed
CVE-2025-55454
was published
Aug 22, 2025
The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to...
High
Unreviewed
CVE-2025-54460
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via a specific service...
Moderate
Unreviewed
CVE-2025-24489
was published
Aug 21, 2025
An attacker could exploit this vulnerability by uploading arbitrary
files via the a specific...
Moderate
Unreviewed
CVE-2025-27714
was published
Aug 21, 2025
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows...
High
Unreviewed
CVE-2025-55383
was published
Aug 21, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a...
Critical
Unreviewed
CVE-2025-53251
was published
Aug 21, 2025
UnoPim vulnerable to remote code execution through Arbitrary File upload
High
CVE-2025-55743
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9296
was published
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API