GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,147 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator allows...
Moderate
Unreviewed
CVE-2025-31888
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31873
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31874
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31890
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31894
was published
Apr 1, 2025
Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-31877
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31895
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31897
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31892
was published
Apr 1, 2025
Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type allows Exploiting...
Moderate
Unreviewed
CVE-2025-31872
was published
Apr 1, 2025
Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code...
Moderate
Unreviewed
CVE-2025-31878
was published
Apr 1, 2025
Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for...
Moderate
Unreviewed
CVE-2025-31879
was published
Apr 1, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Stylemix Pearl allows Cross Site Request...
Moderate
Unreviewed
CVE-2025-31880
was published
Apr 1, 2025
Missing Authorization vulnerability in WPWebinarSystem WebinarPress allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-31882
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31884
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31883
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31891
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31861
was published
Apr 1, 2025
Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-31868
was published
Apr 1, 2025
Missing Authorization vulnerability in Ship Depot ShipDepot for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-31866
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31864
was published
Apr 1, 2025
Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting...
Moderate
Unreviewed
CVE-2025-31862
was published
Apr 1, 2025
Missing Authorization vulnerability in CartBoss SMS Abandoned Cart Recovery ✦ CartBoss allows...
Moderate
Unreviewed
CVE-2025-31865
was published
Apr 1, 2025
Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting...
Moderate
Unreviewed
CVE-2025-31870
was published
Apr 1, 2025
Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-31863
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API