GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,757
NuGet
678
pip
3,444
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
102,660 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23725
was published
Jan 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23730
was published
Jan 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23636
was published
Jan 23, 2025
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’...
High
Unreviewed
CVE-2024-10400
was published
Jan 23, 2025
Unlimited consumption of resources in @fastify/multipart
High
CVE-2025-24033
was published
for
@fastify/multipart
(npm)
Jan 23, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint
High
CVE-2025-24030
was published
for
github.com/envoyproxy/gateway
(Go)
Jan 23, 2025
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
High
CVE-2025-22153
was published
for
RestrictedPython
(pip)
Jan 23, 2025
The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the ...
High
Unreviewed
CVE-2024-13234
was published
Jan 23, 2025
The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions...
High
Unreviewed
CVE-2024-13593
was published
Jan 23, 2025
A file handling command vulnerability in certain versions of Armoury Crate may result in...
High
Unreviewed
CVE-2024-12957
was published
Jan 23, 2025
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent...
High
Unreviewed
CVE-2024-43707
was published
Jan 23, 2025
lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component...
High
Unreviewed
CVE-2024-57722
was published
Jan 23, 2025
For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker...
High
Unreviewed
CVE-2024-11166
was published
Jan 22, 2025
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0...
High
Unreviewed
CVE-2024-56924
was published
Jan 22, 2025
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control...
High
Unreviewed
CVE-2024-55957
was published
Jan 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23809
was published
Jan 22, 2025
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2...
High
Unreviewed
CVE-2024-31903
was published
Jan 22, 2025
The initial code parsing the manifest did not check the content of the file names yet later code...
High
Unreviewed
CVE-2025-0638
was published
Jan 22, 2025
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an...
High
Unreviewed
CVE-2025-20165
was published
Jan 22, 2025
Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
High
CVE-2025-24399
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 22, 2025
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
High
CVE-2025-24398
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Jan 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23966
was published
Jan 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23874
was published
Jan 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23882
was published
Jan 22, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-23910
was published
Jan 22, 2025
ProTip!
Advisories are also available from the
GraphQL API