GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
32,146 advisories
Filter by severity
Malicious input can provoke XSS when preserving comments
Moderate
CVE-2024-23635
was published
for
org.owasp.antisamy:antisamy
(Maven)
Feb 2, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-6673
was published
Feb 2, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-6672
was published
Feb 2, 2024
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to...
Moderate
Unreviewed
CVE-2023-47144
was published
Feb 2, 2024
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2024-0963
was published
Feb 2, 2024
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to...
Moderate
Unreviewed
CVE-2023-51072
was published
Feb 2, 2024
Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote...
Moderate
Unreviewed
CVE-2024-24388
was published
Feb 2, 2024
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows...
Moderate
Unreviewed
CVE-2022-40744
was published
Feb 2, 2024
Dash apps vulnerable to Cross-site Scripting
Moderate
CVE-2024-21485
was published
for
dash
(npm)
Feb 2, 2024
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-1073
was published
Feb 2, 2024
A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base...
Moderate
Unreviewed
CVE-2023-46344
was published
Feb 2, 2024
IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject...
Moderate
Unreviewed
CVE-2023-50933
was published
Feb 2, 2024
Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote...
Moderate
Unreviewed
CVE-2024-23034
was published
Feb 2, 2024
Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote...
Moderate
Unreviewed
CVE-2024-23031
was published
Feb 2, 2024
Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote...
Moderate
Unreviewed
CVE-2024-22927
was published
Feb 2, 2024
Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote...
Moderate
Unreviewed
CVE-2024-23033
was published
Feb 2, 2024
Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker...
Moderate
Unreviewed
CVE-2024-23032
was published
Feb 2, 2024
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with...
Moderate
Unreviewed
CVE-2024-24041
was published
Feb 1, 2024
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with...
Moderate
Unreviewed
CVE-2024-24945
was published
Feb 1, 2024
springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the...
Moderate
Unreviewed
CVE-2024-24059
was published
Feb 1, 2024
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
Moderate
Unreviewed
CVE-2024-24061
was published
Feb 1, 2024
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
Moderate
Unreviewed
CVE-2024-24060
was published
Feb 1, 2024
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
Moderate
Unreviewed
CVE-2024-24062
was published
Feb 1, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-51685
was published
Feb 1, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-51693
was published
Feb 1, 2024
ProTip!
Advisories are also available from the
GraphQL API