GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,518
Maven
5,000+
npm
4,156
NuGet
736
pip
3,955
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37,075 advisories
Filter by severity
A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9715
was published
Sep 10, 2025
Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-40725
was published
Sep 10, 2025
The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-10126
was published
Sep 10, 2025
The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-9857
was published
Sep 10, 2025
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-9367
was published
Sep 10, 2025
The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-8388
was published
Sep 10, 2025
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to...
Moderate
Unreviewed
CVE-2025-49461
was published
Sep 10, 2025
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-7746
was published
Sep 9, 2025
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as ...
Moderate
Unreviewed
CVE-2025-44593
was published
Sep 9, 2025
Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
Moderate
Unreviewed
CVE-2025-44595
was published
Sep 9, 2025
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Moderate
Unreviewed
CVE-2025-55054
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34178
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34177
was published
Sep 9, 2025
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross...
Moderate
Unreviewed
CVE-2025-36125
was published
Sep 9, 2025
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent...
Moderate
Unreviewed
CVE-2025-34172
was published
Sep 9, 2025
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is...
Moderate
Unreviewed
CVE-2025-34174
was published
Sep 9, 2025
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter...
Moderate
Unreviewed
CVE-2025-34175
was published
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attacks via its remote app title field
Moderate
CVE-2025-43775
was published
for
com.liferay:com.liferay.client.extension.web
(Maven)
Sep 9, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter...
Moderate
Unreviewed
CVE-2025-57539
was published
Sep 9, 2025
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter...
Moderate
Unreviewed
CVE-2025-57538
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58982
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58987
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-58984
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API