GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,007 advisories
Filter by severity
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in...
Moderate
Unreviewed
CVE-2025-40694
was published
Sep 11, 2025
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in...
Moderate
Unreviewed
CVE-2025-40696
was published
Sep 11, 2025
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in...
Moderate
Unreviewed
CVE-2025-40693
was published
Sep 11, 2025
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in...
Moderate
Unreviewed
CVE-2025-40695
was published
Sep 11, 2025
The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-9855
was published
Sep 11, 2025
The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-9850
was published
Sep 11, 2025
The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-9860
was published
Sep 11, 2025
The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-9861
was published
Sep 11, 2025
The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-8392
was published
Sep 11, 2025
The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-8398
was published
Sep 11, 2025
The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url'...
Moderate
Unreviewed
CVE-2025-8691
was published
Sep 11, 2025
The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
Moderate
Unreviewed
CVE-2025-8686
was published
Sep 11, 2025
The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
Moderate
Unreviewed
CVE-2025-8721
was published
Sep 11, 2025
The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’...
Moderate
Unreviewed
CVE-2025-9128
was published
Sep 11, 2025
The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-5801
was published
Sep 11, 2025
The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-8316
was published
Sep 11, 2025
The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’...
Moderate
Unreviewed
CVE-2025-8318
was published
Sep 11, 2025
The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-9123
was published
Sep 11, 2025
The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8215
was published
Sep 11, 2025
The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8445
was published
Sep 11, 2025
The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-8689
was published
Sep 11, 2025
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to...
Moderate
Unreviewed
CVE-2025-10246
was published
Sep 11, 2025
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Low
CVE-2025-9910
was published
for
jsondiffpatch
(npm)
Sep 11, 2025
A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of...
Moderate
Unreviewed
CVE-2025-10235
was published
Sep 11, 2025
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code...
Moderate
Unreviewed
CVE-2025-10234
was published
Sep 11, 2025
ProTip!
Advisories are also available from the
GraphQL API