GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,885
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,209
NuGet
744
pip
3,987
Pub
12
RubyGems
950
Rust
1,036
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,275 advisories
Filter by severity
A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown...
Moderate
Unreviewed
CVE-2025-11439
was published
Oct 8, 2025
A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown...
Moderate
Unreviewed
CVE-2025-11438
was published
Oct 8, 2025
The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget...
Moderate
Unreviewed
CVE-2025-9029
was published
Oct 4, 2025
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11228
was published
Oct 4, 2025
The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-9194
was published
Oct 3, 2025
The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of...
Moderate
Unreviewed
CVE-2025-10212
was published
Oct 3, 2025
Missing Authorization vulnerability in HaruTheme Frames allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60165
was published
Sep 26, 2025
Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO allows Exploiting...
Moderate
Unreviewed
CVE-2025-60166
was published
Sep 26, 2025
Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce allows...
Moderate
Unreviewed
CVE-2025-60159
was published
Sep 26, 2025
Missing Authorization vulnerability in Ex-Themes WooEvents allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-60121
was published
Sep 26, 2025
Missing Authorization vulnerability in HivePress HivePress Claim Listings allows Exploiting...
Moderate
Unreviewed
CVE-2025-60123
was published
Sep 26, 2025
Missing Authorization vulnerability in WP Delicious Delisho allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-60128
was published
Sep 26, 2025
Missing Authorization vulnerability in wedos.com WEDOS Global allows Accessing Functionality Not...
Moderate
Unreviewed
CVE-2025-60130
was published
Sep 26, 2025
Missing Authorization vulnerability in loopus WP Virtual Assistant allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-60155
was published
Sep 26, 2025
Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type allows...
Moderate
Unreviewed
CVE-2025-60116
was published
Sep 26, 2025
Missing Authorization vulnerability in wpdirectorykit WP Directory Kit allows Exploiting...
Moderate
Unreviewed
CVE-2025-60120
was published
Sep 26, 2025
Missing Authorization vulnerability in ArtistScope CopySafe Web Protection allows Exploiting...
Moderate
Unreviewed
CVE-2025-60127
was published
Sep 26, 2025
Missing Authorization vulnerability in Yext Yext allows Accessing Functionality Not Properly...
Moderate
Unreviewed
CVE-2025-60129
was published
Sep 26, 2025
Missing Authorization vulnerability in wpshuffle Subscribe to Download allows Exploiting...
Moderate
Unreviewed
CVE-2025-60148
was published
Sep 26, 2025
Missing Authorization vulnerability in netgsm Netgsm allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60143
was published
Sep 26, 2025
Missing Authorization vulnerability in HivePress HivePress Claim Listings allows Exploiting...
Moderate
Unreviewed
CVE-2025-60122
was published
Sep 26, 2025
Missing Authorization vulnerability in wpshuffle Subscribe To Unlock allows Exploiting...
Moderate
Unreviewed
CVE-2025-60152
was published
Sep 26, 2025
Missing Authorization vulnerability in Roxnor EmailKit allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60106
was published
Sep 26, 2025
Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer allows...
Moderate
Unreviewed
CVE-2025-48326
was published
Sep 26, 2025
Missing Authorization vulnerability in Benjamin Intal Stackable allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-60094
was published
Sep 26, 2025
ProTip!
Advisories are also available from the
GraphQL API