GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
279,874 advisories
Filter by severity
The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-13677
was published
Dec 10, 2025
Unprotected service in the AudioLink component allows a local attacker to overwrite system files...
Unknown
Unreviewed
CVE-2025-9056
was published
Dec 10, 2025
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all...
High
Unreviewed
CVE-2025-13339
was published
Dec 10, 2025
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a...
Unknown
Unreviewed
CVE-2025-13072
was published
Dec 10, 2025
The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a...
Unknown
Unreviewed
CVE-2025-13073
was published
Dec 10, 2025
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions...
Critical
Unreviewed
CVE-2025-13613
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-61822
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
Moderate
Unreviewed
CVE-2025-64897
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently...
Moderate
Unreviewed
CVE-2025-64898
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction...
Moderate
Unreviewed
CVE-2025-61823
was published
Dec 10, 2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Unknown
Unreviewed
CVE-2025-13760
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
High
Unreviewed
CVE-2025-61811
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input...
High
Unreviewed
CVE-2025-61812
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input...
Critical
Unreviewed
CVE-2025-61809
was published
Dec 10, 2025
IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server...
Moderate
Unreviewed
CVE-2025-36437
was published
Dec 10, 2025
fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability,...
Unknown
Unreviewed
CVE-2025-65513
was published
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API