GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
126,666 advisories
Filter by severity
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-22673
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-26736
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-26738
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-26734
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22816
was published
Mar 27, 2025
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This...
Moderate
Unreviewed
CVE-2025-2846
was published
Mar 27, 2025
A vulnerability, which was classified as critical, has been found in Codezips Gym Management...
Moderate
Unreviewed
CVE-2025-2847
was published
Mar 27, 2025
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
Moderate
Unreviewed
CVE-2025-31140
was published
Mar 27, 2025
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
Moderate
Unreviewed
CVE-2025-31139
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30925
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30918
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30922
was published
Mar 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce allows...
Moderate
Unreviewed
CVE-2025-30923
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30920
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30907
was published
Mar 27, 2025
Missing Authorization vulnerability in weDevs WP ERP allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-30896
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30904
was published
Mar 27, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Float menu allows Cross Site...
Moderate
Unreviewed
CVE-2025-30912
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30893
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30900
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30903
was published
Mar 27, 2025
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-30897
was published
Mar 27, 2025
Server-Side Request Forgery (SSRF) vulnerability in XpeedStudio Metform allows Server Side...
Moderate
Unreviewed
CVE-2025-30914
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30899
was published
Mar 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30898
was published
Mar 27, 2025
ProTip!
Advisories are also available from the
GraphQL API