GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,144
NuGet
735
pip
3,947
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
378 advisories
Filter by severity
Improper validation of URLs ('Cross-site Scripting') in Wagtail rich text fields
High
CVE-2021-29434
was published
for
wagtail
(pip)
Apr 20, 2021
HTML injection in email and account expiry notifications
Moderate
CVE-2021-21333
was published
for
matrix-synapse
(pip)
Mar 26, 2021
Cross-site scripting (XSS) vulnerability in the password reset endpoint
Moderate
CVE-2021-21332
was published
for
matrix-synapse
(pip)
Mar 26, 2021
lxml vulnerable to Cross-Site Scripting
Moderate
CVE-2021-28957
was published
for
lxml
(pip)
Mar 22, 2021
Cross-site Scripting (XSS) in Django REST Framework
Moderate
CVE-2020-25626
was published
for
djangorestframework
(pip)
Mar 19, 2021
lxml vulnerable to Cross-site Scripting
Moderate
CVE-2020-27783
was published
for
lxml
(pip)
Jan 7, 2021
Denial of service attack via incorrect parameters in Matrix Synapse
High
CVE-2020-26257
was published
for
matrix-synapse
(pip)
Dec 9, 2020
Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability
Moderate
CVE-2020-26249
was published
for
red-dashboard
(pip)
Dec 8, 2020
malicious SVG attachment causing stored XSS vulnerability
Moderate
CVE-2020-15275
was published
for
moin
(pip)
Nov 11, 2020
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
Moderate
CVE-2020-26891
was published
for
matrix-synapse
(pip)
Oct 16, 2020
Stored XSS in Apache Airflow
Moderate
CVE-2020-9485
was published
for
apache-airflow
(pip)
Jul 27, 2020
Multiple stored XSS in RBAC Admin screens in Apache Airflow
Moderate
CVE-2020-11983
was published
for
apache-airflow
(pip)
Jul 27, 2020
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
Moderate
CVE-2020-6816
was published
for
bleach
(pip)
Mar 24, 2020
XSS in Bleach when noscript and raw tag whitelisted
Moderate
CVE-2020-6802
was published
for
bleach
(pip)
Feb 24, 2020
Apache Airflow vulnerable to XSS and local file disclosure
Moderate
CVE-2019-12417
was published
for
airflow
(pip)
Nov 22, 2019
Cross-site scripting in Jupyter Notebook
Moderate
CVE-2018-21030
was published
for
notebook
(pip)
Nov 8, 2019
Cross-site Scripting in django-js-reverse
Moderate
CVE-2019-15486
was published
for
django-js-reverse
(pip)
Aug 27, 2019
Cross-site scripting in recommender-xblock
Moderate
CVE-2018-20858
was published
for
recommender-xblock
(pip)
Aug 21, 2019
Cross-site Scripting in invenio-communities
Moderate
CVE-2019-1020005
was published
for
invenio-communities
(pip)
Jul 16, 2019
ProTip!
Advisories are also available from the
GraphQL API