GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
145,165 advisories
Filter by severity
Missing Authorization vulnerability in Imtiaz Rayhan WP Coupons and Deals wp-coupons-and-deals...
Moderate
Unreviewed
CVE-2025-64241
was published
Dec 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Yoav Farhi RTL Tester rtl-tester allows Cross...
Moderate
Unreviewed
CVE-2025-64239
was published
Dec 16, 2025
Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings...
Moderate
Unreviewed
CVE-2025-64242
was published
Dec 16, 2025
Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm...
Moderate
Unreviewed
CVE-2025-54045
was published
Dec 16, 2025
Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and...
Moderate
Unreviewed
CVE-2025-64244
was published
Dec 16, 2025
The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
Moderate
Unreviewed
CVE-2025-12809
was published
Dec 16, 2025
The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2025-13794
was published
Dec 16, 2025
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or...
Moderate
Unreviewed
CVE-2025-66357
was published
Dec 16, 2025
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI...
Moderate
Unreviewed
CVE-2025-59479
was published
Dec 16, 2025
A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin...
Moderate
Unreviewed
CVE-2025-14777
was published
Dec 16, 2025
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access...
Moderate
Unreviewed
CVE-2025-13956
was published
Dec 16, 2025
Incorrect configuration of replication security in the MariaDB component of the infra-operator in...
Moderate
Unreviewed
CVE-2025-14758
was published
Dec 16, 2025
A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of...
Moderate
Unreviewed
CVE-2025-14749
was published
Dec 16, 2025
An improper neutralization of argument delimiters in a command vulnerability has been reported to...
Moderate
Unreviewed
CVE-2025-62847
was published
Dec 16, 2025
An SQL injection vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-62849
was published
Dec 16, 2025
A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-14748
was published
Dec 16, 2025
A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown...
Moderate
Unreviewed
CVE-2025-14746
was published
Dec 16, 2025
A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2025-14747
was published
Dec 16, 2025
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an...
Moderate
Unreviewed
CVE-2025-14731
was published
Dec 16, 2025
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to...
Moderate
Unreviewed
CVE-2025-9122
was published
Dec 16, 2025
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted...
Moderate
Unreviewed
CVE-2025-14730
was published
Dec 16, 2025
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected...
Moderate
Unreviewed
CVE-2025-14729
was published
Dec 16, 2025
Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to...
Moderate
Unreviewed
CVE-2023-53887
was published
Dec 15, 2025
Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53880
was published
Dec 15, 2025
Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53878
was published
Dec 15, 2025
ProTip!
Advisories are also available from the
GraphQL API