GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
43,940 advisories
Filter by severity
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the...
Moderate
Unreviewed
CVE-2026-68583
was published
Aug 2, 2026
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-12231
was published
Aug 2, 2026
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url...
Moderate
Unreviewed
CVE-2026-67352
was published
Aug 1, 2026
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to...
Moderate
Unreviewed
CVE-2026-67333
was published
Aug 1, 2026
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in...
High
Unreviewed
CVE-2026-67328
was published
Aug 1, 2026
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS...
Moderate
Unreviewed
CVE-2025-71404
was published
Aug 1, 2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon'...
Moderate
Unreviewed
CVE-2026-16685
was published
Aug 1, 2026
The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
Moderate
Unreviewed
CVE-2026-16684
was published
Aug 1, 2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
Moderate
Unreviewed
CVE-2026-17571
was published
Aug 1, 2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-18062
was published
Aug 1, 2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-18435
was published
Aug 1, 2026
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site...
Moderate
Unreviewed
CVE-2026-18344
was published
Aug 1, 2026
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic...
Moderate
Unreviewed
CVE-2026-13458
was published
Aug 1, 2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress...
Moderate
Unreviewed
CVE-2026-16091
was published
Aug 1, 2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2026-15644
was published
Aug 1, 2026
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-15662
was published
Aug 1, 2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress...
Moderate
Unreviewed
CVE-2026-16090
was published
Aug 1, 2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2026-15645
was published
Aug 1, 2026
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2026-15649
was published
Aug 1, 2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks &...
Moderate
Unreviewed
CVE-2026-15950
was published
Aug 1, 2026
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is...
High
Unreviewed
CVE-2026-15052
was published
Aug 1, 2026
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-7623
was published
Aug 1, 2026
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-13362
was published
Aug 1, 2026
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
High
CVE-2026-53608
was published
for
@apostrophecms/seo
(npm)
Jul 31, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API