GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,043 advisories
Filter by severity
An improper neutralization of input during web page generation vulnerability [CWE-79] in...
Moderate
Unreviewed
CVE-2022-38373
was published
Nov 2, 2022
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
Moderate
Unreviewed
CVE-2014-9557
was published
May 13, 2022
Reflected Cross site scripting (XSS) in kairosdb
Moderate
CVE-2019-19040
was published
for
org.kairosdb:kairosdb
(Maven)
Nov 3, 2022
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC...
Moderate
Unreviewed
CVE-2022-35851
was published
Nov 2, 2022
Apache Sling App CMS vulnerable to Cross-site Scripting
Moderate
CVE-2022-43670
was published
for
org.apache.sling:org.apache.sling.cms
(Maven)
Nov 2, 2022
Tribal Systems Zenario CMS vulnerable to Cross-site Scripting
Moderate
CVE-2020-36608
was published
for
tribalsystems/zenario
(Composer)
Nov 3, 2022
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment...
Moderate
Unreviewed
CVE-2011-1264
was published
May 13, 2022
A improper neutralization of input during web page generation ('cross-site scripting') in...
Moderate
Unreviewed
CVE-2022-38374
was published
Nov 2, 2022
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via...
Moderate
Unreviewed
CVE-2022-40840
was published
Nov 2, 2022
An improper neutralization of input during web page generation vulnerability [CWE-79] exists in...
Moderate
Unreviewed
CVE-2022-39950
was published
Nov 2, 2022
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions starting...
Moderate
Unreviewed
CVE-2022-2904
was published
Nov 3, 2022
Simple ASC Content Management System v1.2 has XSS in the location field in the sign function,...
Moderate
Unreviewed
CVE-2017-15947
was published
May 13, 2022
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before...
Moderate
Unreviewed
CVE-2014-0571
was published
May 13, 2022
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site...
Moderate
Unreviewed
CVE-2022-38439
was published
Sep 25, 2022
Reflected Cross-site Scripting in ACS Commons
High
CVE-2021-21028
was published
for
com.adobe.acs:acs-aem-commons
(Maven)
Feb 2, 2021
Inline JS XSS vulnerability in Mautic
Moderate
CVE-2017-1000488
was published
for
mautic/core
(Composer)
Jan 19, 2021
Cross-site Scripting in dompurify
Moderate
CVE-2020-26870
was published
for
dompurify
(npm)
Dec 18, 2020
Cross-site scripting (XSS) in Apache Velocity Tools
Moderate
CVE-2020-13959
was published
for
org.apache.velocity.tools:velocity-tools-parent
(Maven)
Mar 12, 2021
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07...
Moderate
Unreviewed
CVE-2022-3123
was published
Sep 6, 2022
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA...
Moderate
Unreviewed
CVE-2022-36383
was published
Sep 22, 2022
Cross Site Scripting (XSS) in XWiki
Moderate
CVE-2021-3137
was published
for
org.xwiki.commons:xwiki-commons
(Maven)
Jan 29, 2021
XSS in Flarum Sticky extension
Moderate
CVE-2021-21283
was published
for
flarum/sticky
(Composer)
Jan 29, 2021
Cross-site Scripting in vis-timeline
Moderate
CVE-2020-28487
was published
for
vis-timeline
(npm)
Apr 13, 2021
ProTip!
Advisories are also available from the
GraphQL API