GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
270,178 advisories
Filter by severity
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to...
High
Unreviewed
CVE-2025-48466
was published
Jun 26, 2025
A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-6552
was published
Jun 26, 2025
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing...
Critical
Unreviewed
CVE-2025-6559
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload...
Critical
Unreviewed
CVE-2025-48469
was published
Jun 26, 2025
Multiple wireless router models from Sapido have an Exposure of Sensitive Information...
Critical
Unreviewed
CVE-2025-6560
was published
Jun 26, 2025
A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of...
Critical
Unreviewed
CVE-2025-34039
was published
Jun 26, 2025
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint...
Critical
Unreviewed
CVE-2025-34041
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an attacker that has physical access to...
Moderate
Unreviewed
CVE-2025-48468
was published
Jun 26, 2025
A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected...
Moderate
Unreviewed
CVE-2025-6536
was published
Jun 26, 2025
The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-5258
was published
Jun 26, 2025
Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker...
Moderate
Unreviewed
CVE-2025-48470
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct...
Moderate
Unreviewed
CVE-2025-48461
was published
Jun 26, 2025
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit...
High
Unreviewed
CVE-2025-6206
was published
Jun 26, 2025
A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-6551
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an attacker to consume all available...
Moderate
Unreviewed
CVE-2025-48462
was published
Jun 26, 2025
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform 5.0, 5.1 - 5.6sp1, 6.0 -...
Critical
Unreviewed
CVE-2025-34040
was published
Jun 26, 2025
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as...
Moderate
Unreviewed
CVE-2025-6535
was published
Jun 26, 2025
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus...
Moderate
Unreviewed
CVE-2025-6533
was published
Jun 26, 2025
A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by...
High
Unreviewed
CVE-2025-6529
was published
Jun 26, 2025
A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-6530
was published
Jun 26, 2025
A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611....
Moderate
Unreviewed
CVE-2025-6532
was published
Jun 26, 2025
A SQL injection vulnerability exists in Fanwei e-cology 8.0 via the getdata.jsp endpoint. The...
High
Unreviewed
CVE-2025-34038
was published
Jun 26, 2025
An OS command injection vulnerability exists in various models of E-Series Linksys routers via...
Critical
Unreviewed
CVE-2025-34037
was published
Jun 26, 2025
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded...
Critical
Unreviewed
CVE-2025-34034
was published
Jun 26, 2025
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the...
High
Unreviewed
CVE-2025-34031
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API