GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,007 advisories
Filter by severity
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2024-4001
was published
Jun 5, 2024
The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2024-5536
was published
Jun 5, 2024
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &...
Moderate
Unreviewed
CVE-2024-5571
was published
Jun 5, 2024
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2024-1164
was published
Jun 5, 2024
The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2024-5006
was published
Jun 5, 2024
The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for...
Moderate
Unreviewed
CVE-2024-5222
was published
Jun 5, 2024
The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2024-4939
was published
Jun 5, 2024
The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2024-5439
was published
Jun 5, 2024
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2024-4821
was published
Jun 5, 2024
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2024-2087
was published
Jun 5, 2024
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2024-3667
was published
Jun 5, 2024
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2024-1161
was published
Jun 5, 2024
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2024-1940
was published
Jun 5, 2024
The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1'...
Moderate
Unreviewed
CVE-2024-5317
was published
Jun 5, 2024
Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a...
Moderate
Unreviewed
CVE-2024-30889
was published
Jun 5, 2024
ActionText ContentAttachment can Contain Unsanitized HTML
Moderate
CVE-2024-32464
was published
for
actiontext
(RubyGems)
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-34759
was published
Jun 4, 2024
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks...
Moderate
Unreviewed
CVE-2024-0756
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-35782
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-35649
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-35651
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2024-35652
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-35653
was published
Jun 4, 2024
The SolarWinds Platform was determined to be affected by a stored cross-site scripting...
High
Unreviewed
CVE-2024-29004
was published
Jun 4, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-35654
was published
Jun 4, 2024
ProTip!
Advisories are also available from the
GraphQL API