GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,330
Erlang
31
GitHub Actions
21
Go
2,091
Maven
5,000+
npm
3,756
NuGet
678
pip
3,443
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
112,917 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22732
was published
Jan 21, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22825
was published
Jan 21, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-23997
was published
Jan 21, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22718
was published
Jan 21, 2025
Improper Encoding or Escaping of Output vulnerability in Poll Maker Team Poll Maker. This issue...
Moderate
Unreviewed
CVE-2024-56277
was published
Jan 21, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22727
was published
Jan 21, 2025
Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an...
Moderate
Unreviewed
CVE-2025-0614
was published
Jan 21, 2025
Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an...
Moderate
Unreviewed
CVE-2025-0615
was published
Jan 21, 2025
Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to...
Moderate
Unreviewed
CVE-2024-37284
was published
Jan 21, 2025
The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
Moderate
Unreviewed
CVE-2024-13444
was published
Jan 21, 2025
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a...
Moderate
Unreviewed
CVE-2024-52973
was published
Jan 21, 2025
The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2025-0450
was published
Jan 21, 2025
The FireCask Like & Share Button plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-11226
was published
Jan 21, 2025
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress...
Moderate
Unreviewed
CVE-2024-13230
was published
Jan 21, 2025
NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset...
Moderate
Unreviewed
CVE-2024-6466
was published
Jan 21, 2025
The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
Moderate
Unreviewed
CVE-2024-12005
was published
Jan 21, 2025
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-13404
was published
Jan 21, 2025
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12104
was published
Jan 21, 2025
The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several...
Moderate
Unreviewed
CVE-2025-0371
was published
Jan 21, 2025
On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site...
Moderate
Unreviewed
CVE-2025-23086
was published
Jan 21, 2025
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2024-13536
was published
Jan 21, 2025
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13...
Moderate
Unreviewed
CVE-2024-45091
was published
Jan 21, 2025
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more...
Moderate
Unreviewed
CVE-2024-13454
was published
Jan 20, 2025
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin...
Moderate
Unreviewed
CVE-2024-22348
was published
Jan 20, 2025
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be...
Moderate
Unreviewed
CVE-2024-22349
was published
Jan 20, 2025
ProTip!
Advisories are also available from the
GraphQL API