GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
486 advisories
Filter by severity
Cross-Site Scripting in react-marked-markdown
High
GHSA-m7qm-r2r5-f77q
was published
for
react-marked-markdown
(npm)
Sep 1, 2020
Cross-Site Scripting (XSS) in pivottable
High
CVE-2016-1000241
was published
for
pivottable
(npm)
Sep 1, 2020
fuelux vulnerable to Cross-Site Scripting in Pillbox feature
High
CVE-2016-1000235
was published
for
fuelux
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
High
CVE-2016-1000233
was published
for
swagger-ui
(npm)
Sep 1, 2020
XSS in client rendered block templates in rendr
High
CVE-2016-1000230
was published
for
rendr
(npm)
Sep 1, 2020
Cross-Site Scripting in bootstrap-tagsinput
High
CVE-2016-1000227
was published
for
bootstrap-tagsinput
(npm)
Sep 1, 2020
DataTable Vulnerable to Cross-Site Scripting
High
CVE-2015-6584
was published
for
datatables
(Composer)
Aug 31, 2020
Cross-Site Scripting in highcharts
High
GHSA-gr4j-r575-g665
was published
for
highcharts
(npm)
Aug 25, 2020
Cross-Site Scripting in @progress/kendo-angular-editor
High
GHSA-j7wp-vjj6-cp5m
was published
for
@progress/kendo-angular-editor
(npm)
Aug 11, 2020
Stored XSS in TimelineJS3
High
CVE-2020-15092
was published
for
@knight-lab/timelinejs
(npm)
Jul 9, 2020
Cross-site Scripting in Sanitize
High
CVE-2020-4054
was published
for
sanitize
(RubyGems)
Jun 16, 2020
The filename of uploaded files vulnerable to stored XSS
High
CVE-2020-4041
was published
for
bolt/bolt
(Composer)
Jun 9, 2020
Reflected XSS in GraphQL Playground
High
CVE-2020-4038
was published
for
graphql-playground-html
(npm)
Jun 9, 2020
Cross-site scripting vulnerability in TinyMCE
High
CVE-2020-17480
was published
for
tinymce
(npm)
Jan 30, 2020
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
High
CVE-2020-5398
was published
for
org.springframework:spring-webflux
(Maven)
Jan 21, 2020
XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes
High
CVE-2019-18857
was published
for
enshrined/svg-sanitize
(Composer)
Jan 8, 2020
ProTip!
Advisories are also available from the
GraphQL API