GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,128
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,024
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,011 advisories
Filter by severity
Cross-site Scripting in yourls
Moderate
CVE-2021-3785
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
manage (last update Oct 24, 2017) is affected by is affected by a Cross Site Scripting (XSS)...
Moderate
Unreviewed
CVE-2021-43689
was published
Dec 2, 2021
Cross-site Scripting in LibreNMS
Moderate
CVE-2021-44279
was published
for
librenms/librenms
(Composer)
Dec 3, 2021
snipe-it is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4018
was published
for
snipe/snipe-it
(Composer)
Dec 3, 2021
Cross-site Scripting in Gitea
Moderate
CVE-2021-28378
was published
for
code.gitea.io/gitea
(Go)
Sep 27, 2021
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site...
Moderate
Unreviewed
CVE-2022-37238
was published
Aug 26, 2022
Cross-site scripting (XSS) from writer field content in the site frontend
Moderate
CVE-2021-41252
was published
for
getkirby/cms
(Composer)
Nov 16, 2021
pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The...
Moderate
Unreviewed
CVE-2021-43683
was published
Dec 3, 2021
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing...
Moderate
Unreviewed
CVE-2015-20106
was published
Dec 3, 2021
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
Moderate
Unreviewed
CVE-2021-33495
was published
Nov 23, 2021
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic...
Moderate
Unreviewed
CVE-2021-24875
was published
Nov 24, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability...
Moderate
Unreviewed
CVE-2021-20493
was published
Dec 4, 2021
Cross-site Scripting in XXL-JOB
Moderate
CVE-2020-29204
was published
for
com.xuxueli:xxl-job-core
(Maven)
Oct 12, 2021
Authenticated Stored XSS in shopware/shopware
Moderate
CVE-2021-41188
was published
for
shopware/shopware
(Composer)
Oct 27, 2021
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware...
Moderate
Unreviewed
CVE-2019-10887
was published
May 13, 2022
Cross-site Scripting in apostrophe
Moderate
CVE-2021-25978
was published
for
apostrophe
(npm)
Nov 10, 2021
Cross-Site Scripting Vulnerability in @joeattardi/emoji-button
High
CVE-2021-43785
was published
for
@joeattardi/emoji-button
(npm)
Dec 1, 2021
Cross-Site Scripting vulnerability in @backstage/plugin-auth-backend
High
CVE-2021-43776
was published
for
@backstage/plugin-auth-backend
(npm)
Dec 1, 2021
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome...
Moderate
Unreviewed
CVE-2021-36919
was published
Nov 27, 2021
Cross-site scripting (XSS) was possible in notification pop-ups. The following products are...
Moderate
Unreviewed
CVE-2021-44201
was published
Nov 30, 2021
The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or...
Moderate
Unreviewed
CVE-2021-24918
was published
Nov 30, 2021
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent...
Moderate
Unreviewed
CVE-2019-2413
was published
May 13, 2022
The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social...
Moderate
Unreviewed
CVE-2021-24745
was published
Nov 30, 2021
Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s...
Moderate
Unreviewed
CVE-2021-42118
was published
Dec 1, 2021
ProTip!
Advisories are also available from the
GraphQL API