GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,075 advisories
Filter by severity
Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to...
Moderate
Unreviewed
CVE-2025-21037
was published
Sep 9, 2025
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local...
Moderate
Unreviewed
CVE-2023-21483
was published
Sep 9, 2025
Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views...
Moderate
Unreviewed
CVE-2025-55944
was published
Sep 9, 2025
An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1...
Moderate
Unreviewed
CVE-2025-56498
was published
Sep 9, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
YesWiki Cross Site Scripting vulnerability
Moderate
CVE-2025-52277
was published
for
yeswiki/yeswiki
(Composer)
Sep 9, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
Moderate
Unreviewed
CVE-2024-45325
was published
Sep 9, 2025
A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10107
was published
Sep 9, 2025
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by...
Moderate
Unreviewed
CVE-2025-47416
was published
Sep 9, 2025
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7...
Moderate
Unreviewed
CVE-2025-53609
was published
Sep 9, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
A SQL injection vulnerability has been identified in the SMPP server component of the SMSEagle...
Moderate
Unreviewed
CVE-2025-10095
was published
Sep 9, 2025
TYPO3 backend modules have Broken Access Control
Moderate
CVE-2025-59017
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CSV download feature information disclosure
Moderate
CVE-2025-59019
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS exposes sensitive information in an error message
Moderate
CVE-2025-59016
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 Bookmark Toolbar vulnerable to denial of service
Moderate
CVE-2025-59014
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS uses insufficient entropy when generating passwords
Moderate
CVE-2025-59015
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 CMS has an open‑redirect vulnerability
Moderate
CVE-2025-59013
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS...
Moderate
Unreviewed
CVE-2025-40594
was published
Sep 9, 2025
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC...
Moderate
Unreviewed
CVE-2025-40757
was published
Sep 9, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in...
Moderate
Unreviewed
CVE-2025-9542
was published
Sep 9, 2025
The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes...
Moderate
Unreviewed
CVE-2025-9061
was published
Sep 9, 2025
The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of...
Moderate
Unreviewed
CVE-2025-9111
was published
Sep 9, 2025
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2025-9489
was published
Sep 9, 2025
The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes...
Moderate
Unreviewed
CVE-2025-9058
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API