GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,019 advisories
Filter by severity
GraphiQL introspection schema template injection attack
High
CVE-2021-41248
was published
for
graphiql
(npm)
Nov 8, 2021
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries...
Critical
Unreviewed
CVE-2018-9079
was published
May 13, 2022
Unsafe defaults in `remark-html`
Critical
CVE-2021-39199
was published
for
remark-html
(npm)
Sep 7, 2021
The "WPO365 | LOGIN" WordPress plugin (up to and including version 15.3) by wpo365.com is...
Moderate
Unreviewed
CVE-2021-43409
was published
Nov 20, 2021
Cross-site Scripting in snipe/snipe-it
High
CVE-2021-3961
was published
for
snipe/snipe-it
(Composer)
Nov 23, 2021
Cross-site Scripting in peertube
Moderate
CVE-2021-3780
was published
for
peertube
(npm)
Sep 20, 2021
Cross-site Scripting in yourls
Moderate
CVE-2021-3783
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector...
Moderate
Unreviewed
CVE-2021-40131
was published
Nov 20, 2021
Cross-site Scripting in OpenCRX
Moderate
CVE-2021-25959
was published
for
org.opencrx:opencrx-client
(Maven)
Sep 30, 2021
Cross-site scripting in application/controllers/dropbox.php in JustWriting
Moderate
CVE-2021-41467
was published
for
hjue/justwriting
(Composer)
Oct 4, 2021
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails...
Moderate
Unreviewed
CVE-2019-0858
was published
May 13, 2022
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the...
Moderate
Unreviewed
CVE-2022-37160
was published
Aug 26, 2022
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
Moderate
Unreviewed
CVE-2021-33489
was published
Nov 23, 2021
Cross-site scripting vulnerability in file upload
High
CVE-2021-39136
was published
for
baserproject/basercms
(Composer)
Aug 30, 2021
Cross site scripting in kindeditor
Moderate
CVE-2021-42227
was published
for
kindeditor
(npm)
Oct 18, 2021
Cross-site Scripting in Limesurvey
Moderate
CVE-2021-42112
was published
for
limesurvey/limesurvey
(Composer)
Oct 12, 2021
Cross-site Scripting in snipe-it
Moderate
CVE-2021-3863
was published
for
snipe/snipe-it
(Composer)
Oct 21, 2021
Cross-Site Scripting in grav
Moderate
CVE-2021-3904
was published
for
getgrav/grav
(Composer)
Nov 1, 2021
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly...
High
Unreviewed
CVE-2019-0668
was published
May 13, 2022
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts...
Moderate
Unreviewed
CVE-2021-43295
was published
Dec 1, 2021
The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before...
Moderate
Unreviewed
CVE-2017-20008
was published
Nov 30, 2021
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before...
Moderate
Unreviewed
CVE-2021-24908
was published
Nov 30, 2021
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v...
Moderate
Unreviewed
CVE-2021-24876
was published
Nov 30, 2021
An unspecified version of issabelPBX is affected by a Cross Site Scripting (XSS) vulnerability....
Moderate
Unreviewed
CVE-2021-43695
was published
Nov 30, 2021
Reflected cross-site scripting in vaadin-menu-bar webjar resources in Vaadin 14
Moderate
CVE-2021-33611
was published
for
com.vaadin:vaadin-bom
(Maven)
Nov 3, 2021
ProTip!
Advisories are also available from the
GraphQL API