GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,301 advisories
Filter by severity
A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon...
Moderate
Unreviewed
CVE-2025-3312
was published
Apr 6, 2025
Kentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for...
Moderate
Unreviewed
CVE-2025-32369
was published
Apr 6, 2025
A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0....
Moderate
Unreviewed
CVE-2025-3311
was published
Apr 6, 2025
In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see...
Moderate
Unreviewed
CVE-2025-32360
was published
Apr 5, 2025
In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When...
Moderate
Unreviewed
CVE-2025-32359
was published
Apr 5, 2025
A vulnerability, which was classified as critical, has been found in code-projects Patient Record...
Moderate
Unreviewed
CVE-2025-3303
was published
Apr 5, 2025
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy,...
Moderate
Unreviewed
CVE-2024-56370
was published
Apr 5, 2025
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to...
Moderate
Unreviewed
CVE-2025-32357
was published
Apr 5, 2025
In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in...
Moderate
Unreviewed
CVE-2025-32358
was published
Apr 5, 2025
The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build...
Moderate
Unreviewed
CVE-2025-2789
was published
Apr 5, 2025
The Lafka Plugin for WordPress is vulnerable to unauthorized access due to a missing capability...
Moderate
Unreviewed
CVE-2025-1233
was published
Apr 5, 2025
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote...
Moderate
Unreviewed
CVE-2025-32352
was published
Apr 5, 2025
The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes...
Moderate
Unreviewed
CVE-2025-0839
was published
Apr 5, 2025
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2024-11088
was published
Apr 5, 2025
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link...
Moderate
Unreviewed
CVE-2025-2889
was published
Apr 5, 2025
A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0....
Moderate
Unreviewed
CVE-2025-3265
was published
Apr 4, 2025
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-3268
was published
Apr 4, 2025
A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to...
Moderate
Unreviewed
CVE-2025-3266
was published
Apr 4, 2025
A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0....
Moderate
Unreviewed
CVE-2025-3267
was published
Apr 4, 2025
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Moderate
GHSA-4fcv-w3qc-ppgg
was published
for
openssl
(Rust)
Apr 4, 2025
Buffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit...
Moderate
Unreviewed
CVE-2025-29476
was published
Apr 4, 2025
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the...
Moderate
Unreviewed
CVE-2025-29477
was published
Apr 4, 2025
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-32277
was published
Apr 4, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z allows Cross Site...
Moderate
Unreviewed
CVE-2025-32276
was published
Apr 4, 2025
Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual allows Cross...
Moderate
Unreviewed
CVE-2025-32278
was published
Apr 4, 2025
ProTip!
Advisories are also available from the
GraphQL API