GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131,663 advisories
Filter by severity
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector...
Moderate
Unreviewed
CVE-2025-20166
was published
Jan 8, 2025
Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network...
Moderate
Unreviewed
CVE-2025-20123
was published
Jan 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/sti: avoid potential...
Moderate
Unreviewed
CVE-2024-56776
was published
Jan 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
btrfs: add a sanity check...
Moderate
Unreviewed
CVE-2024-56774
was published
Jan 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/sti: avoid potential...
Moderate
Unreviewed
CVE-2024-56777
was published
Jan 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
mtd: spinand: winbond: Fix...
Moderate
Unreviewed
CVE-2024-56771
was published
Jan 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
net/sched: netem: account...
Moderate
Unreviewed
CVE-2024-56770
was published
Jan 8, 2025
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-11830
was published
Jan 8, 2025
The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross...
Moderate
Unreviewed
CVE-2024-12337
was published
Jan 8, 2025
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2024-12712
was published
Jan 8, 2025
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-9673
was published
Jan 8, 2025
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and...
Moderate
Unreviewed
CVE-2024-12851
was published
Jan 8, 2025
The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
Moderate
Unreviewed
CVE-2024-12328
was published
Jan 8, 2025
A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this...
Moderate
Unreviewed
CVE-2024-8002
was published
Jan 8, 2025
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13186
was published
Jan 8, 2025
The health module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13173
was published
Jan 8, 2025
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13185
was published
Jan 8, 2025
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2024-12852
was published
Jan 8, 2025
The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2024-12855
was published
Jan 8, 2025
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious...
Moderate
Unreviewed
CVE-2025-22215
was published
Jan 8, 2025
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress...
Moderate
Unreviewed
CVE-2024-12045
was published
Jan 8, 2025
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12584
was published
Jan 8, 2025
cpdf through 2.8 allows stack consumption via a crafted PDF document.
Moderate
Unreviewed
CVE-2024-54731
was published
Jan 8, 2025
Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an...
Moderate
Unreviewed
CVE-2025-21603
was published
Jan 8, 2025
ProTip!
Advisories are also available from the
GraphQL API