GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,762
Maven
5,000+
npm
4,371
NuGet
767
pip
4,141
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
146,214 advisories
Filter by severity
The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-13365
was published
Dec 20, 2025
The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-14735
was published
Dec 20, 2025
The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-14721
was published
Dec 20, 2025
The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data...
Moderate
Unreviewed
CVE-2025-14633
was published
Dec 20, 2025
The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site...
Moderate
Unreviewed
CVE-2025-13624
was published
Dec 20, 2025
After a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters...
Moderate
Unreviewed
CVE-2025-14591
was published
Dec 20, 2025
The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due...
Moderate
Unreviewed
CVE-2025-12898
was published
Dec 20, 2025
The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-14164
was published
Dec 20, 2025
The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-12581
was published
Dec 20, 2025
The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-14734
was published
Dec 20, 2025
The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-14168
was published
Dec 20, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-14968
was published
Dec 19, 2025
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-14967
was published
Dec 19, 2025
There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior...
Moderate
Unreviewed
CVE-2025-67712
was published
Dec 19, 2025
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53953
was published
Dec 19, 2025
A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The...
Moderate
Unreviewed
CVE-2025-14961
was published
Dec 19, 2025
A vulnerability was found in 1541492390c yougou-mall up to...
Moderate
Unreviewed
CVE-2025-14965
was published
Dec 19, 2025
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in...
Moderate
Unreviewed
CVE-2025-12874
was published
Dec 19, 2025
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function...
Moderate
Unreviewed
CVE-2025-14966
was published
Dec 19, 2025
A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an...
Moderate
Unreviewed
CVE-2025-14962
was published
Dec 19, 2025
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
Moderate
CVE-2025-68481
was published
for
fastapi-users
(pip)
Dec 19, 2025
A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some...
Moderate
Unreviewed
CVE-2025-14959
was published
Dec 19, 2025
A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function...
Moderate
Unreviewed
CVE-2025-14957
was published
Dec 19, 2025
Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows...
Moderate
Unreviewed
CVE-2025-66906
was published
Dec 19, 2025
ProTip!
Advisories are also available from the
GraphQL API