GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
378 advisories
Filter by severity
Cross-site scripting in Unicorn framework
Moderate
CVE-2021-42053
was published
for
django-unicorn
(pip)
Oct 12, 2021
Cross-site Scripting in django-unicorn
Moderate
CVE-2021-42134
was published
for
django-unicorn
(pip)
Oct 12, 2021
Cross Site Scripting (XSS) in Simiki
Moderate
CVE-2020-19000
was published
for
simiki
(pip)
Sep 1, 2021
Cross Site Scripting (XSS) in Quokka
Moderate
CVE-2020-18702
was published
for
quokka
(pip)
Aug 30, 2021
Special Element Injection in notebook
High
CVE-2021-32798
was published
for
notebook
(pip)
Aug 23, 2021
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Moderate
CVE-2021-32797
was published
for
jupyterlab
(pip)
Aug 23, 2021
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
Moderate
CVE-2021-33507
was published
for
Plone
(pip)
Jun 18, 2021
Cross-site Scripting in Apache Airflow
Moderate
CVE-2021-28359
was published
for
apache-airflow
(pip)
Jun 18, 2021
Cross-site scripting in LocalStack
Moderate
CVE-2021-32091
was published
for
localstack
(pip)
Jun 18, 2021
Cross-site scripting in Contentful
Moderate
CVE-2020-13258
was published
for
contentful
(pip)
Jun 18, 2021
Apache Airflow Cross-site Scripting
Moderate
CVE-2020-13944
was published
for
apache-airflow
(pip)
Jun 18, 2021
Cross-site Scripting in wagtail
Moderate
CVE-2021-32681
was published
for
wagtail
(pip)
Jun 17, 2021
Duplicate Advisory: Reflected cross-site scripting issue in Datasette
High
GHSA-gff3-739c-gxfq
was published
for
datasette
(pip)
Jun 10, 2021
•
withdrawn
Header injection possible in Django
Moderate
CVE-2021-32052
was published
for
Django
(pip)
Jun 9, 2021
Reflected cross-site scripting issue in Datasette
Moderate
CVE-2021-32670
was published
for
datasette
(pip)
Jun 7, 2021
LinkedIn Oncall vulnerable to Cross-Site Scripting
Moderate
CVE-2021-26722
was published
for
oncall
(pip)
Apr 30, 2021
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
Moderate
CVE-2020-17515
was published
for
apache-airflow
(pip)
Apr 20, 2021
Cross-site scripting in papermerge
Moderate
CVE-2020-29456
was published
for
papermerge
(pip)
Apr 20, 2021
Cross-site scripting in SiCKRAGE
Moderate
CVE-2021-25925
was published
for
sickrage
(pip)
Apr 20, 2021
Cross-site scripting in sickrage
Moderate
CVE-2021-25926
was published
for
sickrage
(pip)
Apr 20, 2021
ProTip!
Advisories are also available from the
GraphQL API