GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
743 advisories
Filter by severity
Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia...
Moderate
Unreviewed
CVE-2025-49060
was published
Oct 22, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual...
Moderate
Unreviewed
CVE-2025-60187
was published
Nov 6, 2025
A security vulnerability has been detected in code-projects Content Management System 1.0....
Moderate
Unreviewed
CVE-2026-0566
was published
Jan 2, 2026
Umbraco CMS has an arbitrary file upload vulnerability
Moderate
CVE-2025-67288
was published
for
Umbraco.Cms
(NuGet)
Dec 22, 2025
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to...
Moderate
Unreviewed
CVE-2025-15503
was published
Jan 10, 2026
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of...
Moderate
Unreviewed
CVE-2025-15495
was published
Jan 9, 2026
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that...
Moderate
Unreviewed
CVE-2021-47899
was published
Jan 23, 2026
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files,...
Moderate
Unreviewed
CVE-2025-8889
was published
Sep 9, 2025
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1....
Moderate
Unreviewed
CVE-2025-1555
was published
Feb 21, 2025
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training...
Moderate
Unreviewed
CVE-2025-54944
was published
Sep 25, 2025
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads...
Moderate
Unreviewed
CVE-2026-21625
was published
Jan 16, 2026
A non-administrative user can upload malicious files. When an administrator or the product...
Moderate
Unreviewed
CVE-2026-23704
was published
Feb 4, 2026
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted...
Moderate
Unreviewed
CVE-2026-1152
was published
Jan 19, 2026
An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing...
Moderate
Unreviewed
CVE-2025-69618
was published
Feb 4, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18...
Moderate
Unreviewed
CVE-2026-1458
was published
Feb 11, 2026
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the...
Moderate
Unreviewed
CVE-2026-2146
was published
Feb 8, 2026
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-12500
was published
Feb 19, 2026
A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some...
Moderate
Unreviewed
CVE-2026-2164
was published
Feb 8, 2026
ProTip!
Advisories are also available from the
GraphQL API