GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
808 advisories
Filter by severity
Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing...
High
Unreviewed
CVE-2024-38726
was published
Nov 1, 2024
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly...
High
Unreviewed
CVE-2024-38721
was published
Nov 1, 2024
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing...
High
Unreviewed
CVE-2024-39650
was published
Nov 1, 2024
Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting...
High
Unreviewed
CVE-2024-37106
was published
Nov 1, 2024
Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting...
High
Unreviewed
CVE-2024-37232
was published
Nov 1, 2024
Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not...
High
Unreviewed
CVE-2024-37470
was published
Nov 1, 2024
Access Control vulnerability in StylemixThemes MasterStudy LMS allows .
This issue affects...
High
Unreviewed
CVE-2024-37094
was published
Nov 1, 2024
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is...
High
Unreviewed
CVE-2024-10008
was published
Oct 29, 2024
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia...
High
Unreviewed
CVE-2024-44208
was published
Oct 28, 2024
A path deletion vulnerability was addressed by preventing vulnerable code from running with...
High
Unreviewed
CVE-2024-44156
was published
Oct 28, 2024
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
High
Unreviewed
CVE-2024-10402
was published
Oct 26, 2024
Missing Authorization vulnerability in ReneeCussack 3D Work In Progress allows Exploiting...
High
Unreviewed
CVE-2024-49657
was published
Oct 23, 2024
In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization ...
High
Unreviewed
CVE-2024-48645
was published
Oct 21, 2024
The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification,...
High
Unreviewed
CVE-2024-10078
was published
Oct 18, 2024
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing...
High
Unreviewed
CVE-2022-4972
was published
Oct 16, 2024
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization...
High
Unreviewed
CVE-2020-36840
was published
Oct 16, 2024
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized...
High
Unreviewed
CVE-2023-7294
was published
Oct 16, 2024
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized...
High
Unreviewed
CVE-2023-7291
was published
Oct 16, 2024
The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability...
High
Unreviewed
CVE-2019-25214
was published
Oct 16, 2024
The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file...
High
Unreviewed
CVE-2019-25215
was published
Oct 16, 2024
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in...
High
Unreviewed
CVE-2021-4447
was published
Oct 16, 2024
The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in...
High
Unreviewed
CVE-2021-4444
was published
Oct 16, 2024
The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in...
High
Unreviewed
CVE-2021-4448
was published
Oct 16, 2024
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive...
High
Unreviewed
CVE-2024-38190
was published
Oct 16, 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
High
Unreviewed
CVE-2024-21234
was published
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API