GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
32,144 advisories
Filter by severity
The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-9849
was published
Sep 6, 2025
The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-9853
was published
Sep 6, 2025
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8360
was published
Sep 6, 2025
The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-6067
was published
Sep 6, 2025
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-10027
was published
Sep 6, 2025
A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in...
Moderate
Unreviewed
CVE-2025-10044
was published
Sep 5, 2025
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-10026
was published
Sep 5, 2025
The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-9057
was published
Sep 5, 2025
A vulnerability was detected in O2OA up to 10.0-410. Affected is an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9737
was published
Sep 5, 2025
A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part...
Moderate
Unreviewed
CVE-2025-9728
was published
Sep 5, 2025
A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the...
Moderate
Unreviewed
CVE-2025-9735
was published
Sep 5, 2025
A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-9736
was published
Sep 5, 2025
A vulnerability has been found in Khanakag-17 Library Management System up to...
Moderate
Unreviewed
CVE-2025-9755
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-48102
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-48105
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-48103
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-8695
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58883
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58876
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58880
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58884
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58887
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58886
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58882
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58862
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API