GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
24,125 advisories
Filter by severity
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress...
Critical
Unreviewed
CVE-2025-13377
was published
Dec 6, 2025
The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2025-12673
was published
Dec 6, 2025
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account...
Critical
Unreviewed
CVE-2025-34291
was published
Dec 6, 2025
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an...
Critical
Unreviewed
CVE-2025-53963
was published
Dec 4, 2025
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are...
Critical
Unreviewed
CVE-2025-54303
was published
Dec 4, 2025
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are...
Critical
Unreviewed
CVE-2025-54304
was published
Dec 4, 2025
An exposure of sensitive information vulnerability has been reported to affect Media Streaming...
Critical
Unreviewed
CVE-2023-47222
was published
Apr 26, 2024
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2024-5853
was published
Jun 19, 2024
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial...
Critical
Unreviewed
CVE-2025-65868
was published
Dec 3, 2025
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local...
Critical
Unreviewed
CVE-2025-64055
was published
Dec 3, 2025
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities....
Critical
Unreviewed
CVE-2023-49666
was published
Jan 4, 2024
Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key...
Critical
Unreviewed
CVE-2025-34256
was published
Dec 5, 2025
ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution...
Critical
Unreviewed
CVE-2020-36877
was published
Dec 5, 2025
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and...
Critical
Unreviewed
CVE-2025-55469
was published
Nov 26, 2025
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a...
Critical
Unreviewed
CVE-2017-20005
was published
May 24, 2022
The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login ...
Critical
Unreviewed
CVE-2025-12374
was published
Dec 5, 2025
The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset...
Critical
Unreviewed
CVE-2025-13313
was published
Dec 5, 2025
FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via...
Critical
Unreviewed
CVE-2025-50402
was published
Nov 26, 2025
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in...
Critical
Unreviewed
CVE-2025-66571
was published
Dec 4, 2025
FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via...
Critical
Unreviewed
CVE-2025-50399
was published
Nov 26, 2025
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that...
Critical
Unreviewed
CVE-2025-11625
was published
Oct 21, 2025
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers...
Critical
Unreviewed
CVE-2015-5224
was published
May 13, 2022
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user...
Critical
Unreviewed
CVE-2025-59695
was published
Dec 2, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation...
Critical
Unreviewed
CVE-2024-45538
was published
Dec 4, 2025
Improper input validation together with an integer overflow in the EAP-TLS protocol...
Critical
Unreviewed
CVE-2018-11574
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API