GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,890
Maven
5,000+
npm
4,540
NuGet
785
pip
4,279
Pub
12
RubyGems
978
Rust
1,106
Swift
49
Unreviewed advisories
All unreviewed
5,000+
148,994 advisories
Filter by severity
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-14274
was published
Feb 3, 2026
A
vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an
authenticated attacker with...
Moderate
Unreviewed
CVE-2025-58381
was published
Feb 3, 2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-0950
was published
Feb 3, 2026
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with...
Moderate
Unreviewed
CVE-2025-58380
was published
Feb 3, 2026
The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
Moderate
Unreviewed
CVE-2026-0909
was published
Feb 3, 2026
: Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol...
Moderate
Unreviewed
CVE-2026-1788
was published
Feb 3, 2026
A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the...
Moderate
Unreviewed
CVE-2026-24935
was published
Feb 3, 2026
The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate...
Moderate
Unreviewed
CVE-2026-24934
was published
Feb 3, 2026
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection...
Moderate
Unreviewed
CVE-2025-12774
was published
Feb 3, 2026
Brocade Fabric OS before 9.2.1 has a vulnerability that could allow a local authenticated...
Moderate
Unreviewed
CVE-2025-58379
was published
Feb 3, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Moderate
Unreviewed
CVE-2025-6590
was published
Feb 3, 2026
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00...
Moderate
Unreviewed
CVE-2025-36238
was published
Feb 3, 2026
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby...
Moderate
Unreviewed
CVE-2025-12680
was published
Feb 3, 2026
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could...
Moderate
Unreviewed
CVE-2025-36253
was published
Feb 3, 2026
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0...
Moderate
Unreviewed
CVE-2025-36436
was published
Feb 3, 2026
Magento's X-Original-Url header can expose admin url
Moderate
GHSA-jg68-vhv3-9r8f
was published
for
openmage/magento-lts
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation
Moderate
GHSA-h9r9-2pxg-cx9m
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
Moderate
CVE-2026-25490
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation
Moderate
CVE-2026-25489
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Moderate
CVE-2026-25488
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation
Moderate
CVE-2026-25487
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation
Moderate
CVE-2026-25486
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation
Moderate
CVE-2026-25485
was published
for
craftcms/composer
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS in Product Type Name
Moderate
CVE-2026-25484
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration
Moderate
CVE-2026-25483
was published
for
craftcms/commerce
(Composer)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API