GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,923 advisories
Filter by severity
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
High
Unreviewed
CVE-2025-55422
was published
Aug 27, 2025
Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis...
High
Unreviewed
CVE-2025-30036
was published
Aug 27, 2025
A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise...
High
Unreviewed
CVE-2025-3478
was published
Aug 26, 2025
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows...
High
Unreviewed
CVE-2025-55409
was published
Aug 26, 2025
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered....
High
Unreviewed
CVE-2025-54301
was published
Aug 25, 2025
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered....
High
Unreviewed
CVE-2025-54300
was published
Aug 25, 2025
A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of...
High
Unreviewed
CVE-2025-5352
was published
Aug 23, 2025
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
High
Unreviewed
CVE-2025-55573
was published
Aug 22, 2025
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6....
High
Unreviewed
CVE-2025-55420
was published
Aug 21, 2025
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the...
High
Unreviewed
CVE-2025-51991
was published
Aug 20, 2025
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
High
Unreviewed
CVE-2025-57731
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54032
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54044
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54670
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54056
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54055
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54027
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53212
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53563
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53564
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53319
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53205
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53559
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53562
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53226
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API