GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131,665 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter allows Cross...
Moderate
Unreviewed
CVE-2025-49269
was published
Jun 6, 2025
Missing Authorization vulnerability in cmoreira Testimonials Showcase allows Exploiting...
Moderate
Unreviewed
CVE-2025-49246
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under...
Moderate
Unreviewed
CVE-2025-49284
was published
Jun 6, 2025
Missing Authorization vulnerability in cmoreira Team Showcase allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49248
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross...
Moderate
Unreviewed
CVE-2025-49291
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder allows Cross...
Moderate
Unreviewed
CVE-2025-49286
was published
Jun 6, 2025
Missing Authorization vulnerability in sergiotrinity Trinity Audio allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49272
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA...
Moderate
Unreviewed
CVE-2025-49285
was published
Jun 6, 2025
Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post...
Moderate
Unreviewed
CVE-2025-49293
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49306
was published
Jun 6, 2025
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder...
Moderate
Unreviewed
CVE-2025-49292
was published
Jun 6, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic...
Moderate
Unreviewed
CVE-2025-49294
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection,...
Moderate
Unreviewed
CVE-2025-49283
was published
Jun 6, 2025
Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49289
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49301
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49304
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49299
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site...
Moderate
Unreviewed
CVE-2025-49273
was published
Jun 6, 2025
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-49287
was published
Jun 6, 2025
Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality...
Moderate
Unreviewed
CVE-2025-49270
was published
Jun 6, 2025
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49288
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49298
was published
Jun 6, 2025
Missing Authorization vulnerability in raychat Raychat allows Accessing Functionality Not...
Moderate
Unreviewed
CVE-2025-49236
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49235
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49244
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API