GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
165 advisories
Filter by severity
Gophish vulnerable to Cross-site Scripting via crafted landing page
Moderate
CVE-2022-45004
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
Answer vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-1536
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-1535
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
imgproxy Cross-site Scripting vulnerability
Moderate
CVE-2023-1496
was published
for
github.com/imgproxy/imgproxy/v3
(Go)
Mar 19, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1241
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1240
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1239
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1237
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1243
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1238
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1242
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1244
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1245
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Moderate
CVE-2023-22462
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
teler-waf contains detection rule bypass via Entities payload
Moderate
CVE-2023-26047
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
teler-waf subject to Bypass of Common Web Attack Threat Rule with HTML Entities Payload
Moderate
CVE-2023-26046
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
Grafana vulnerable to Cross-site Scripting
Moderate
CVE-2023-0594
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
Grafana vulnerable to Cross-site Scripting
Moderate
CVE-2023-0507
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-0934
was published
for
github.com/answerdev/answer
(Go)
Feb 21, 2023
Cross Site Scripting in usememos/memos
Moderate
CVE-2022-25978
was published
for
github.com/usememos/memos
(Go)
Feb 15, 2023
Answer subject to Cross-site Scripting vulnerability
Critical
CVE-2023-0743
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
Answer has Cross-site Scripting vulnerability
Critical
CVE-2023-0741
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
Answer contains Cross-site Scripting vulnerability
Critical
CVE-2023-0742
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
Cross-site scripting vulnerability found in answerdev/answer
Critical
CVE-2023-0740
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
Reflected XSS in Gotify's /docs via import of outdated Swagger UI
Moderate
GHSA-3244-8mff-w398
was published
for
github.com/gotify/server
(Go)
Jan 10, 2023
ProTip!
Advisories are also available from the
GraphQL API