GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,966
NuGet
713
pip
3,759
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,716 advisories
Filter by severity
The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter...
High
Unreviewed
CVE-2024-13632
was published
Feb 26, 2025
The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter...
High
Unreviewed
CVE-2024-13633
was published
May 20, 2025
The WordPress Activity O Meter WordPress plugin through 1.0 does not sanitise and escape a...
High
Unreviewed
CVE-2024-13668
was published
Mar 7, 2025
The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings,...
High
Unreviewed
CVE-2024-3594
was published
May 23, 2024
The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its...
High
Unreviewed
CVE-2024-4290
was published
May 21, 2024
The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through...
High
Unreviewed
CVE-2024-13862
was published
Mar 11, 2025
Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the...
High
Unreviewed
CVE-2025-2261
was published
May 21, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-32285
was published
May 23, 2025
The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-1123
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46526
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46537
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47458
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-31636
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47611
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46440
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46487
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46515
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47613
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46448
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39505
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39502
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46456
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46446
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46437
was published
May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47618
was published
May 23, 2025
ProTip!
Advisories are also available from the
GraphQL API