Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

37,019 advisories

Loading
GraphiQL introspection schema template injection attack High
CVE-2021-41248 was published for graphiql (npm) Nov 8, 2021
Ry0taK
Unsafe defaults in `remark-html` Critical
CVE-2021-39199 was published for remark-html (npm) Sep 7, 2021
matthieusieben
Cross-site Scripting in snipe/snipe-it High
CVE-2021-3961 was published for snipe/snipe-it (Composer) Nov 23, 2021
Cross-site Scripting in peertube Moderate
CVE-2021-3780 was published for peertube (npm) Sep 20, 2021
Cross-site Scripting in yourls Moderate
CVE-2021-3783 was published for yourls/yourls (Composer) Sep 20, 2021
Cross-site Scripting in OpenCRX Moderate
CVE-2021-25959 was published for org.opencrx:opencrx-client (Maven) Sep 30, 2021
Cross-site scripting in application/controllers/dropbox.php in JustWriting Moderate
CVE-2021-41467 was published for hjue/justwriting (Composer) Oct 4, 2021
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. Moderate Unreviewed
CVE-2021-33489 was published Nov 23, 2021
Cross-site scripting vulnerability in file upload High
CVE-2021-39136 was published for baserproject/basercms (Composer) Aug 30, 2021
Cross site scripting in kindeditor Moderate
CVE-2021-42227 was published for kindeditor (npm) Oct 18, 2021
Cross-site Scripting in Limesurvey Moderate
CVE-2021-42112 was published for limesurvey/limesurvey (Composer) Oct 12, 2021
Cross-site Scripting in snipe-it Moderate
CVE-2021-3863 was published for snipe/snipe-it (Composer) Oct 21, 2021
Cross-Site Scripting in grav Moderate
CVE-2021-3904 was published for getgrav/grav (Composer) Nov 1, 2021
Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14 Moderate
CVE-2021-33611 was published for com.vaadin:vaadin-bom (Maven) Nov 3, 2021
ProTip! Advisories are also available from the GraphQL API