GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
23,434 advisories
Filter by severity
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via...
Critical
Unreviewed
CVE-2025-58462
was published
Sep 9, 2025
An authentication bypass vulnerability allows remote attackers to gain administrative privileges...
Critical
Unreviewed
CVE-2025-10159
was published
Sep 9, 2025
Use of Default Cryptographic Key (CWE-1394)
Critical
Unreviewed
CVE-2025-55049
was published
Sep 9, 2025
CWE-1242: Inclusion of Undocumented Features
Critical
Unreviewed
CVE-2025-55050
was published
Sep 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow allows Code Injection. This issue...
Critical
Unreviewed
CVE-2025-58997
was published
Sep 9, 2025
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an...
Critical
Unreviewed
CVE-2025-55232
was published
Sep 9, 2025
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation...
Critical
Unreviewed
CVE-2025-54261
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects...
Critical
Unreviewed
CVE-2025-47579
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-47569
was published
Sep 9, 2025
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material...
Critical
Unreviewed
CVE-2025-32486
was published
Sep 9, 2025
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect...
Critical
Unreviewed
CVE-2025-10183
was published
Sep 9, 2025
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and...
Critical
Unreviewed
CVE-2025-54236
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions...
Critical
Unreviewed
CVE-2025-40804
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
Critical
Unreviewed
CVE-2025-40795
was published
Sep 9, 2025
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2025-10134
was published
Sep 9, 2025
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw...
Critical
Unreviewed
CVE-2025-42922
was published
Sep 9, 2025
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could...
Critical
Unreviewed
CVE-2025-42944
was published
Sep 9, 2025
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the...
Critical
Unreviewed
CVE-2025-42958
was published
Sep 9, 2025
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to...
Critical
Unreviewed
CVE-2025-9114
was published
Sep 8, 2025
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to missing file type...
Critical
Unreviewed
CVE-2025-9113
was published
Sep 8, 2025
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows...
Critical
Unreviewed
CVE-2025-56267
was published
Sep 8, 2025
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib...
Critical
Unreviewed
CVE-2025-57285
was published
Sep 8, 2025
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute...
Critical
Unreviewed
CVE-2025-56266
was published
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API