GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
834 advisories
Filter by severity
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-12171
was published
Feb 1, 2025
The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2024-13767
was published
Jan 31, 2025
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2024-23962
was published
Jan 31, 2025
The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can...
High
Unreviewed
CVE-2024-12129
was published
Jan 30, 2025
The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access...
High
Unreviewed
CVE-2024-12269
was published
Jan 30, 2025
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of...
High
Unreviewed
CVE-2024-12821
was published
Jan 30, 2025
The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation &...
High
Unreviewed
CVE-2024-10591
was published
Jan 30, 2025
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-21396
was published
Jan 30, 2025
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass...
High
Unreviewed
CVE-2024-40677
was published
Jan 28, 2025
Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege...
High
Unreviewed
CVE-2025-24734
was published
Jan 27, 2025
Missing Authorization vulnerability in Marian Kanev Cab fare calculator allows Stored XSS. This...
High
Unreviewed
CVE-2025-23982
was published
Jan 27, 2025
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead...
High
Unreviewed
CVE-2024-11936
was published
Jan 26, 2025
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-10574
was published
Jan 26, 2025
Missing Authorization vulnerability in Team118GROUP Team 118GROUP Agent allows Exploiting...
High
Unreviewed
CVE-2025-23512
was published
Jan 22, 2025
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant...
High
Unreviewed
CVE-2024-49732
was published
Jan 22, 2025
Missing Authorization vulnerability in Realty Workstation Realty Workstation allows Accessing...
High
Unreviewed
CVE-2025-23477
was published
Jan 21, 2025
Missing Authorization vulnerability in Eniture Technology Standard Box Sizes – for WooCommerce....
High
Unreviewed
CVE-2025-22318
was published
Jan 21, 2025
Missing Authorization vulnerability in Joe Dolson My Tickets allows Accessing Functionality Not...
High
Unreviewed
CVE-2025-22717
was published
Jan 21, 2025
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot...
High
Unreviewed
CVE-2018-9382
was published
Jan 18, 2025
The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due...
High
Unreviewed
CVE-2024-12614
was published
Jan 16, 2025
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low...
High
Unreviewed
CVE-2024-57726
was published
Jan 16, 2025
An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a...
High
Unreviewed
CVE-2024-50953
was published
Jan 15, 2025
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a...
High
Unreviewed
CVE-2024-11848
was published
Jan 15, 2025
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a...
High
Unreviewed
CVE-2024-12365
was published
Jan 14, 2025
The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a...
High
Unreviewed
CVE-2024-12848
was published
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API