GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+ Composer
5,000+ Erlang
39 GitHub Actions
38 Go
2,750 Maven
5,000+ npm
4,353 NuGet
765 pip
4,114 Pub
12 RubyGems
960 Rust
1,069 Swift
45Unreviewed advisories
All unreviewed
5,000+5,621 advisories
Filter by severity
Uh oh!
There was an error while loading. Please reload this page.
The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to... Moderate Unreviewed
CVE-2025-14074 was published Dec 12, 2025
The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a... Moderate Unreviewed
CVE-2025-14065 was published Dec 12, 2025
The WP Fastest Cache plugin for WordPress is vulnerable to Server-Side Request Forgery in all... Low Unreviewed
CVE-2025-10583 was published Dec 12, 2025
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write... Moderate Unreviewed
CVE-2025-12655 was published Dec 12, 2025
The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data... Moderate Unreviewed
CVE-2025-14392 was published Dec 12, 2025
The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all... Moderate Unreviewed
CVE-2025-14170 was published Dec 12, 2025
The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due... Moderate Unreviewed
CVE-2025-14045 was published Dec 12, 2025
The BuddyTask plugin for WordPress is vulnerable to unauthorized access and modification of data... Moderate Unreviewed
CVE-2025-14064 was published Dec 12, 2025
The Flow-Flow Social Feed Stream plugin for WordPress is vulnerable to unauthorized modification... Moderate Unreviewed
CVE-2025-13866 was published Dec 12, 2025
The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for... Critical Unreviewed
CVE-2025-12963 was published Dec 12, 2025
The Product Filtering by Categories, Tags, Price Range for WooCommerce – Filter Plus plugin for... Moderate Unreviewed
CVE-2025-13314 was published Dec 12, 2025
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and... High Unreviewed
CVE-2025-13334 was published Dec 12, 2025
The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing... Moderate Unreviewed
CVE-2025-13440 was published Dec 12, 2025
The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized... Moderate Unreviewed
CVE-2025-12783 was published Dec 12, 2025
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE Low
CVE-2025-67737 was published for azuracast/azuracast (Composer) Dec 11, 2025
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that... Critical Unreviewed
CVE-2020-36902 was published Dec 10, 2025
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to... High Unreviewed
CVE-2023-53740 was published Dec 10, 2025
Jenkins is missing a permission check on password fields Moderate
CVE-2025-67636 was published for org.jenkins-ci.main:jenkins-core (Maven) Dec 10, 2025
OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by... High Unreviewed
CVE-2021-47701 was published Dec 9, 2025
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly... Moderate Unreviewed
CVE-2023-23729 was published Dec 9, 2025
Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting... Moderate Unreviewed
CVE-2022-46845 was published Dec 9, 2025
Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly... Moderate Unreviewed
CVE-2022-47425 was published Dec 9, 2025
Missing Authorization vulnerability in ThimPress Sailing sailing allows Exploiting Incorrectly... Unknown Unreviewed
CVE-2025-67573 was published Dec 9, 2025
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting... Moderate Unreviewed
CVE-2025-67563 was published Dec 9, 2025
Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly... Unknown Unreviewed
CVE-2025-67572 was published Dec 9, 2025
ProTip! Advisories are also available from the GraphQL API