GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,629
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,149
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
3,818 advisories
Filter by severity
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file...
Critical
Unreviewed
CVE-2025-9314
was published
Sep 2, 2026
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files...
Critical
Unreviewed
CVE-2026-4357
was published
Sep 2, 2026
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
High
CVE-2026-81891
was published
for
Studio-42/elFinder
(Composer)
Sep 2, 2026
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up...
High
Unreviewed
CVE-2026-19513
was published
Sep 1, 2026
This vulnerability exists in the ERP system due to improper authentication controls and...
Critical
Unreviewed
CVE-2026-84147
was published
Sep 1, 2026
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode...
Critical
Unreviewed
CVE-2026-75865
was published
Sep 1, 2026
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Critical
Unreviewed
CVE-2026-81780
was published
Aug 31, 2026
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice...
Critical
Unreviewed
CVE-2026-82970
was published
Aug 31, 2026
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix...
High
Unreviewed
CVE-2026-78078
was published
Aug 31, 2026
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP...
High
Unreviewed
CVE-2026-82450
was published
Aug 29, 2026
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions...
Critical
Unreviewed
CVE-2026-14494
was published
Aug 29, 2026
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request...
Moderate
Unreviewed
CVE-2026-79706
was published
Aug 28, 2026
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross...
High
Unreviewed
CVE-2026-18983
was published
Aug 28, 2026
Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero...
Moderate
Unreviewed
CVE-2026-81931
was published
Aug 27, 2026
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Critical
Unreviewed
CVE-2026-78274
was published
Aug 27, 2026
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event...
Critical
Unreviewed
CVE-2026-77991
was published
Aug 27, 2026
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate...
High
Unreviewed
CVE-2026-77018
was published
Aug 27, 2026
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and...
Moderate
Unreviewed
CVE-2026-75331
was published
Aug 27, 2026
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller...
Critical
Unreviewed
CVE-2026-75327
was published
Aug 26, 2026
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North...
Critical
Unreviewed
CVE-2025-61165
was published
Aug 26, 2026
CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary...
High
Unreviewed
CVE-2026-80233
was published
Aug 26, 2026
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability....
High
Unreviewed
CVE-2026-80237
was published
Aug 26, 2026
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is...
Critical
Unreviewed
CVE-2026-18080
was published
Aug 26, 2026
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability....
Critical
Unreviewed
CVE-2026-80235
was published
Aug 26, 2026
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to...
High
Unreviewed
CVE-2026-80050
was published
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API