GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
XWiki Blog Application: Privilege Escalation (PR) from account through blog content
High
CVE-2025-58365
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Sep 8, 2025
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability...
Moderate
Unreviewed
CVE-2025-55585
was published
Aug 18, 2025
The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version...
High
Unreviewed
CVE-2025-8420
was published
Aug 6, 2025
PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user...
Critical
Unreviewed
CVE-2013-10070
was published
Aug 5, 2025
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to...
Critical
Unreviewed
CVE-2013-10051
was published
Aug 1, 2025
OZI-Project/ozi-publish Code Injection vulnerability
Moderate
CVE-2025-47271
was published
for
OZI-Project/publish
(GitHub Actions)
May 12, 2025
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the...
Critical
Unreviewed
CVE-2025-26845
was published
May 8, 2025
com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations
Critical
CVE-2025-27603
was published
for
com.xwiki.confluencepro:application-confluence-migrator-pro-ui
(Maven)
Mar 7, 2025
XWiki Platform allows remote code execution as guest via SolrSearchMacros request
Critical
CVE-2025-24893
was published
for
org.xwiki.platform:xwiki-platform-search-solr-ui
(Maven)
Feb 20, 2025
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
Critical
CVE-2024-36404
was published
for
org.geotools.xsd:gt-xsd-core
(Maven)
Feb 5, 2025
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary...
High
Unreviewed
CVE-2024-10633
was published
Jan 26, 2025
The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to...
Critical
Unreviewed
CVE-2024-8512
was published
Oct 30, 2024
Butterfly's parseJSON, getJSON functions eval malicious input, leading to remote code execution (RCE)
Moderate
GHSA-mpcw-3j5p-p99x
was published
for
org.openrefine.dependencies:butterfly
(Maven)
Oct 24, 2024
LangChain Experimental Eval Injection vulnerability
Critical
CVE-2024-46946
was published
for
langchain-experimental
(pip)
Sep 19, 2024
Chaosblade vulnerable to OS command execution
Critical
CVE-2023-47105
was published
for
github.com/chaosblade-io/chaosblade
(Go)
Sep 18, 2024
Guardrails has an arbitrary code execution vulnerability
High
CVE-2024-45858
was published
for
guardrails-ai
(pip)
Sep 18, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45851
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45850
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45848
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45849
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45847
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45846
was published
for
mindsdb
(pip)
Sep 12, 2024
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27321
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27320
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API