GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
215 advisories
Filter by severity
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-30676
was published
Apr 1, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31604
was published
Mar 31, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31575
was published
Mar 31, 2025
Duplicate Advisory: Leantime affected by Improper Neutralization of HTML Tags
Moderate
GHSA-jf6p-4hgv-v6qh
was published
for
leantime/leantime
(Composer)
Mar 28, 2025
•
withdrawn
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31465
was published
Mar 28, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31075
was published
Mar 28, 2025
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and...
Moderate
Unreviewed
CVE-2025-1997
was published
Mar 27, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29426
was published
Mar 17, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29427
was published
Mar 17, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29430
was published
Mar 17, 2025
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise...
Moderate
Unreviewed
CVE-2025-25363
was published
Mar 13, 2025
A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User...
Moderate
Unreviewed
CVE-2025-28015
was published
Mar 13, 2025
An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML...
Moderate
Unreviewed
CVE-2024-34398
was published
Mar 12, 2025
Froxlor has an HTML Injection Vulnerability
Moderate
CVE-2025-48958
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate
CVE-2025-27155
was published
for
github.com/matrix-org/pinecone
(Go)
Mar 4, 2025
Formwork has a cross-site scripting (XSS) vulnerability in Site title
Moderate
GHSA-vf6x-59hh-332f
was published
for
getformwork/formwork
(Composer)
Mar 1, 2025
Leantime affected by Improper Neutralization of HTML Tags
Moderate
CVE-2025-28254
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package
Moderate
CVE-2025-25299
was published
for
@ckeditor/ckeditor5-real-time-collaboration
(npm)
Feb 20, 2025
PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name,...
Moderate
Unreviewed
CVE-2023-51308
was published
Feb 20, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
is vulnerable to HTML injection, caused...
Moderate
Unreviewed
CVE-2024-49337
was published
Feb 20, 2025
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Moderate
CVE-2024-46910
was published
for
org.apache.atlas:apache-atlas
(Maven)
Feb 13, 2025
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker...
Moderate
Unreviewed
CVE-2024-38318
was published
Feb 6, 2025
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated...
Moderate
Unreviewed
CVE-2024-57004
was published
Feb 3, 2025
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2024-35112
was published
Jan 25, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-24673
was published
Jan 24, 2025
ProTip!
Advisories are also available from the
GraphQL API