GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            27,327 advisories
        Filter by severity
        
      
      
    
                    
                      Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43995
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Karmada Dashboard API Unauthorized Access Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62714
                      
                      was published
                        for
                        
                          github.com/karmada-io/dashboard
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6440
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11253
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61934
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Server-side request forgery (ssrf) in Azure Compute Gallery allows an authorized attacker to...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59503
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58428
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11023
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12104
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47699
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62023
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62025
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60225
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in axiomthemes White Rabbit whiterabbit allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60226
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60232
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60238
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60213
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60214
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59557
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58967
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60039
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58958
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58963
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52758
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Missing Authorization vulnerability in vanquish WooCommerce Orders & Customers Exporter...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53424
                      
                      was published
                      Oct 22, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API