GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287,824 advisories
Filter by severity
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation...
Moderate
Unreviewed
CVE-2025-8469
was published
Aug 2, 2025
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation...
Moderate
Unreviewed
CVE-2025-8470
was published
Aug 2, 2025
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-8468
was published
Aug 2, 2025
The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-6722
was published
Aug 2, 2025
A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-8467
was published
Aug 2, 2025
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for...
Moderate
Unreviewed
CVE-2025-8488
was published
Aug 2, 2025
The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in...
Critical
Unreviewed
CVE-2025-7710
was published
Aug 2, 2025
The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-7500
was published
Aug 2, 2025
The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-4588
was published
Aug 2, 2025
The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for...
Moderate
Unreviewed
CVE-2025-6832
was published
Aug 2, 2025
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing...
High
Unreviewed
CVE-2025-6754
was published
Aug 2, 2025
The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-8317
was published
Aug 2, 2025
The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-8391
was published
Aug 2, 2025
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-8466
was published
Aug 2, 2025
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-6626
was published
Aug 2, 2025
The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-8212
was published
Aug 2, 2025
The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-8399
was published
Aug 2, 2025
The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-8152
was published
Aug 2, 2025
The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all...
Moderate
Unreviewed
CVE-2025-8400
was published
Aug 2, 2025
The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to...
Moderate
Unreviewed
CVE-2025-7694
was published
Aug 2, 2025
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-8146
was published
Aug 2, 2025
Partner Software's Partner Software application and Partner Web application do not sanitize files...
Unknown
Unreviewed
CVE-2025-6076
was published
Aug 2, 2025
Partner Software's Partner Software Product and corresponding Partner Web application use the...
Unknown
Unreviewed
CVE-2025-6077
was published
Aug 2, 2025
Partner Software's Partner Software application and Partner Web application allows an...
Unknown
Unreviewed
CVE-2025-6078
was published
Aug 2, 2025
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local...
High
Unreviewed
CVE-2025-0217
was published
May 5, 2025
ProTip!
Advisories are also available from the
GraphQL API