GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
27,115 advisories
Filter by severity
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability...
Critical
Unreviewed
CVE-2025-59741
was published
Oct 2, 2025
SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker...
Critical
Unreviewed
CVE-2025-59743
was published
Oct 2, 2025
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate...
Critical
Unreviewed
CVE-2025-41064
was published
Oct 2, 2025
The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a...
Critical
Unreviewed
CVE-2025-9697
was published
Oct 2, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted...
Critical
Unreviewed
CVE-2025-11221
was published
Oct 2, 2025
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
Critical
CVE-2025-61588
was published
for
risc0-aggregation
(Rust)
Oct 1, 2025
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each...
Critical
Unreviewed
CVE-2025-52549
was published
Oct 1, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61044
was published
Oct 1, 2025
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability...
Critical
Unreviewed
CVE-2025-61045
was published
Oct 1, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2020-36852
was published
Oct 1, 2025
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to...
Critical
Unreviewed
CVE-2025-10659
was published
Sep 30, 2025
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an...
Critical
Unreviewed
CVE-2025-10725
was published
Sep 30, 2025
NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital...
Critical
Unreviewed
CVE-2025-56513
was published
Sep 30, 2025
A privilege escalation flaw from host to domain administrator was found in FreeIPA. This...
Critical
Unreviewed
CVE-2025-7493
was published
Sep 30, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments)...
Critical
Unreviewed
CVE-2025-34217
was published
Sep 30, 2025
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
Critical
Unreviewed
CVE-2025-9762
was published
Sep 30, 2025
Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows...
Critical
Unreviewed
CVE-2025-7065
was published
Sep 30, 2025
Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows...
Critical
Unreviewed
CVE-2025-7063
was published
Sep 30, 2025
The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via...
Critical
Unreviewed
CVE-2025-8625
was published
Sep 30, 2025
Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows...
Critical
Unreviewed
CVE-2025-8120
was published
Sep 30, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
Critical
Unreviewed
CVE-2024-58040
was published
Sep 30, 2025
An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru...
Critical
Unreviewed
CVE-2025-57266
was published
Sep 29, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and...
Critical
Unreviewed
CVE-2025-34234
was published
Sep 29, 2025
ProTip!
Advisories are also available from the
GraphQL API