GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,936 advisories
Filter by severity
A vulnerability, which was classified as critical, has been found in withstars Books-Management...
Moderate
Unreviewed
CVE-2025-3963
was published
Apr 27, 2025
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical...
Moderate
Unreviewed
CVE-2025-3960
was published
Apr 27, 2025
The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized...
High
Unreviewed
CVE-2025-3906
was published
Apr 26, 2025
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data...
Moderate
Unreviewed
CVE-2025-3915
was published
Apr 26, 2025
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS)....
High
Unreviewed
CVE-2025-37088
was published
Apr 23, 2025
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-3912
was published
Apr 25, 2025
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data...
High
Unreviewed
CVE-2025-1279
was published
Apr 25, 2025
Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows...
Moderate
Unreviewed
CVE-2025-46535
was published
Apr 25, 2025
Missing Authorization vulnerability in Peter Raschendorfer Smart Hashtags [#hashtagger] allows...
Moderate
Unreviewed
CVE-2025-46470
was published
Apr 24, 2025
Missing Authorization vulnerability in Carlo La Pera WP Customize Login Page allows Accessing...
Moderate
Unreviewed
CVE-2025-46485
was published
Apr 24, 2025
Missing Authorization vulnerability in Michael Revellin-Clerc Media Library Downloader allows...
Moderate
Unreviewed
CVE-2025-46519
was published
Apr 24, 2025
Missing Authorization vulnerability in VW Themes Sirat allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-39385
was published
Apr 24, 2025
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing...
Moderate
Unreviewed
CVE-2025-39390
was published
Apr 24, 2025
Missing Authorization vulnerability in vinodvaswani9 Bulk Assign Linked Products For WooCommerce...
Moderate
Unreviewed
CVE-2025-46489
was published
Apr 24, 2025
Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by...
High
Unreviewed
CVE-2021-47662
was published
Apr 24, 2025
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover...
Critical
Unreviewed
CVE-2025-3604
was published
Apr 24, 2025
The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that...
High
Unreviewed
CVE-2025-3058
was published
Apr 24, 2025
The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2024-13307
was published
Apr 24, 2025
An issue has been discovered in access controls could allow users to view certain restricted...
Moderate
Unreviewed
CVE-2024-12244
was published
Apr 24, 2025
In wlan driver, there is a possible missing permission check, This could lead to local...
Moderate
Unreviewed
CVE-2022-42782
was published
Dec 6, 2022
In wlan driver, there is a possible missing permission check, This could lead to local...
Moderate
Unreviewed
CVE-2022-42766
was published
Dec 6, 2022
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an...
Critical
Unreviewed
CVE-2025-37087
was published
Apr 22, 2025
Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1...
High
Unreviewed
CVE-2025-1021
was published
Apr 23, 2025
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location...
Low
Unreviewed
CVE-2022-20240
was published
Dec 13, 2022
Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce allows...
Moderate
Unreviewed
CVE-2025-46244
was published
Apr 22, 2025
ProTip!
Advisories are also available from the
GraphQL API