GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131,652 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49301
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49304
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49299
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site...
Moderate
Unreviewed
CVE-2025-49273
was published
Jun 6, 2025
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-49287
was published
Jun 6, 2025
Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality...
Moderate
Unreviewed
CVE-2025-49270
was published
Jun 6, 2025
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49288
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49298
was published
Jun 6, 2025
Missing Authorization vulnerability in raychat Raychat allows Accessing Functionality Not...
Moderate
Unreviewed
CVE-2025-49236
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49235
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49244
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49242
was published
Jun 6, 2025
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services allows...
Moderate
Unreviewed
CVE-2025-30997
was published
Jun 6, 2025
Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-31000
was published
Jun 6, 2025
Missing Authorization vulnerability in bobbingwide oik allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-49241
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes...
Moderate
Unreviewed
CVE-2025-49239
was published
Jun 6, 2025
Missing Authorization vulnerability in nK DocsPress allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-49240
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30991
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31025
was published
Jun 6, 2025
Missing Authorization vulnerability in Soft8Soft LLC Verge3D allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49268
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site...
Moderate
Unreviewed
CVE-2025-49238
was published
Jun 6, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase...
Moderate
Unreviewed
CVE-2025-49250
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49243
was published
Jun 6, 2025
Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks allows Server Side Request...
Moderate
Unreviewed
CVE-2025-30976
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-30951
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API