GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
130 advisories
Filter by severity
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Moderate
CVE-2025-48934
was published
for
deno
(Rust)
Jun 4, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2025-5733
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic...
Moderate
Unreviewed
CVE-2025-49294
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX...
High
Unreviewed
CVE-2025-48261
was published
Jun 9, 2025
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe...
Moderate
Unreviewed
CVE-2025-53309
was published
Jun 27, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize...
Moderate
Unreviewed
CVE-2025-53322
was published
Jun 27, 2025
In ConnectWise PSA versions older than 2025.9, a
vulnerability exists where authenticated users...
Moderate
Unreviewed
CVE-2025-7204
was published
Jul 9, 2025
YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include...
High
Unreviewed
CVE-2025-8862
was published
Aug 11, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Liquid Web GiveWP allows...
High
Unreviewed
CVE-2025-47444
was published
Aug 12, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash...
Moderate
Unreviewed
CVE-2025-54685
was published
Aug 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows...
Moderate
Unreviewed
CVE-2025-55710
was published
Aug 14, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows...
Moderate
Unreviewed
CVE-2025-49408
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine allows...
Moderate
Unreviewed
CVE-2025-53196
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTabs allows...
Moderate
Unreviewed
CVE-2025-53985
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks allows...
Moderate
Unreviewed
CVE-2025-53992
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetMenu allows...
Moderate
Unreviewed
CVE-2025-53987
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetPopup allows...
Moderate
Unreviewed
CVE-2025-53993
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetElements For...
Moderate
Unreviewed
CVE-2025-53983
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetSmartFilters...
Moderate
Unreviewed
CVE-2025-54008
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetBlocks For...
Moderate
Unreviewed
CVE-2025-53988
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetWooBuilder...
Moderate
Unreviewed
CVE-2025-53998
was published
Aug 20, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg...
High
Unreviewed
CVE-2025-55715
was published
Aug 20, 2025
The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to...
High
Unreviewed
CVE-2025-41415
was published
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API