GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,575 advisories
Filter by severity
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
High
CVE-2025-58358
was published
for
mcp-markdownify-server
(npm)
Sep 2, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-9518
was published
Sep 4, 2025
A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function...
High
Unreviewed
CVE-2025-9938
was published
Sep 4, 2025
Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to...
High
Unreviewed
CVE-2024-34598
was published
Sep 4, 2025
The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to...
High
Unreviewed
CVE-2025-6085
was published
Sep 4, 2025
The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to,...
High
Unreviewed
CVE-2025-9517
was published
Sep 4, 2025
The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
High
Unreviewed
CVE-2025-9519
was published
Sep 4, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano...
High
Unreviewed
CVE-2025-2411
was published
Sep 4, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat...
High
Unreviewed
CVE-2025-2417
was published
Sep 4, 2025
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle...
High
Unreviewed
CVE-2024-47258
was published
Feb 6, 2025
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
High
GHSA-ph6w-f82w-28w6
was published
for
@anthropic-ai/claude-code
(npm)
Sep 3, 2025
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL...
High
Unreviewed
CVE-2025-58644
was published
Sep 3, 2025
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes –...
High
Unreviewed
CVE-2025-58643
was published
Sep 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-58637
was published
Sep 3, 2025
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day &...
High
Unreviewed
CVE-2025-58642
was published
Sep 3, 2025
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in...
High
Unreviewed
CVE-2025-57150
was published
Sep 3, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58604
was published
Sep 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-58608
was published
Sep 3, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk...
High
Unreviewed
CVE-2025-2416
was published
Sep 3, 2025
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability...
High
Unreviewed
CVE-2025-47421
was published
Sep 3, 2025
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin...
High
Unreviewed
CVE-2025-57151
was published
Sep 3, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore...
High
Unreviewed
CVE-2025-53694
was published
Sep 3, 2025
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue...
High
Unreviewed
CVE-2024-13068
was published
Sep 3, 2025
ProTip!
Advisories are also available from the
GraphQL API