wpscan maintains a vulnerability database at https://wpvulndb.com/
a plugin you can add to your site: https://wordpress.org/plugins/plugin-security-scanner/
It will alert you if any of your plugins have vulnerabilities. It uses the wpscan database
Then there is https://www.exploit-db.com/ which goes beyond wordpress.
And .... if you are a gluten for more there is the cve details
http://www.cvedetails.com/