GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
112 advisories
Filter by severity
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
Network access can be used to execute arbitrary code with elevated privileges.
This
issue...
Critical
Unreviewed
CVE-2024-48841
was published
Jan 27, 2025
The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local...
Critical
Unreviewed
CVE-2024-9193
was published
Feb 28, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-26916
was published
Mar 10, 2025
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
Critical
Unreviewed
CVE-2025-1771
was published
Mar 15, 2025
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable...
Critical
Unreviewed
CVE-2024-13790
was published
Mar 19, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-28916
was published
Mar 26, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-26909
was published
Mar 27, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-32577
was published
Apr 11, 2025
A improper control of filename for include/require statement in PHP program vulnerability in the...
Critical
Unreviewed
CVE-2025-31340
was published
Apr 17, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-39406
was published
May 19, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-46468
was published
May 23, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-47586
was published
Jun 6, 2025
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is...
Critical
Unreviewed
CVE-2025-4689
was published
Jul 2, 2025
File contents could be read from the local file system by an attacker. Additionally, malicious...
Critical
Unreviewed
CVE-2025-24937
was published
Jul 21, 2025
The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file...
Critical
Unreviewed
CVE-2012-10025
was published
Aug 5, 2025
Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability,...
Critical
Unreviewed
CVE-2025-8913
was published
Aug 13, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-25174
was published
Aug 14, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-48293
was published
Aug 14, 2025
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is...
Critical
Unreviewed
CVE-2025-7721
was published
Oct 3, 2025
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is...
Critical
Unreviewed
CVE-2025-7634
was published
Oct 9, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-58958
was published
Oct 22, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-58967
was published
Oct 22, 2025
Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for...
Critical
Unreviewed
CVE-2025-11023
was published
Oct 23, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2025-39463
was published
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API