GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
486 advisories
Filter by severity
Cross-site Scripting in electron-pdf
High
CVE-2024-1648
was published
for
electron-pdf
(npm)
Feb 20, 2024
Magento Open Source allows Cross-Site Scripting (XSS)
High
CVE-2024-20719
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
XSS sidekiq-unique-jobs UI server vulnerability
High
CVE-2024-25122
was published
for
sidekiq-unique-jobs
(RubyGems)
Feb 13, 2024
October CMS Cross-site Scripting vulnerability
High
CVE-2023-25365
was published
for
october/october
(Composer)
Feb 9, 2024
Statmic CMS vulnerable to account takeover via XSS and password reset link
High
CVE-2024-24570
was published
for
statamic/cms
(Composer)
Feb 1, 2024
@urql/next Cross-site Scripting vulnerability
High
CVE-2024-24556
was published
for
@urql/next
(npm)
Jan 30, 2024
react-query-streamed-hydration Cross-site Scripting vulnerability
High
CVE-2024-24558
was published
for
@tanstack/react-query-next-experimental
(npm)
Jan 30, 2024
Content-Security-Policy disabled by Red Hat Dependency Analytics Jenkins Plugin
High
CVE-2024-23905
was published
for
io.jenkins.plugins:redhat-dependency-analytics
(Maven)
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
High
CVE-2023-47115
was published
for
label-studio
(pip)
Jan 24, 2024
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
High
CVE-2024-23345
was published
for
nautobot
(pip)
Jan 23, 2024
avo vulnerable to stored cross-site scripting (XSS) in key_value field
High
CVE-2024-22191
was published
for
avo
(RubyGems)
Jan 16, 2024
PrestaShop some attribute not escaped in Validate::isCleanHTML method
High
CVE-2024-21627
was published
for
prestashop/prestashop
(Composer)
Jan 3, 2024
Cross Site Request Forgery in Silverpeas
High
CVE-2023-47322
was published
for
org.silverpeas.core:silverpeas-core-web
(Maven)
Dec 13, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
High
GHSA-9j5w-2cqc-cwj9
was published
for
openmage/magento-lts
(Composer)
Dec 8, 2023
Improper Neutralization of Input in Advanced User Interface for Jolt
High
CVE-2023-49145
was published
for
org.apache.nifi:nifi-jolt-transform-json-ui
(Maven)
Nov 28, 2023
Cross-site Scripting potential in custom links, job buttons, and computed fields
High
CVE-2023-48705
was published
for
nautobot
(pip)
Nov 22, 2023
Cross-site Scripting via uploaded assets
High
CVE-2023-48701
was published
for
statamic/cms
(Composer)
Nov 22, 2023
phpMyFAQ Cross-site Scripting vulnerability
High
CVE-2023-5864
was published
for
thorsten/phpmyfaq
(Composer)
Oct 31, 2023
Jenkins Edgewall Trac Plugin vulnerable to Stored XSS
High
CVE-2023-46659
was published
for
org.jenkins-ci.plugins:trac
(Maven)
Oct 25, 2023
Stored XSS vulnerability in Jenkins GitHub Plugin
High
CVE-2023-46650
was published
for
com.coravy.hudson.plugins.github:github
(Maven)
Oct 25, 2023
modoboa Cross-site Scripting vulnerability
High
CVE-2023-5689
was published
for
modoboa
(pip)
Oct 20, 2023
Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context
High
CVE-2023-45815
was published
for
archivebox
(pip)
Oct 19, 2023
Cross-site Scripting via missing Binding syntax validation
High
CVE-2023-45683
was published
for
github.com/crewjam/saml
(Go)
Oct 17, 2023
phpMyFAQ Cross-site Scripting vulnerability
High
CVE-2023-5319
was published
for
thorsten/phpmyfaq
(Composer)
Sep 30, 2023
Jenkins Cross-site Scripting vulnerability
High
CVE-2023-43495
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 20, 2023
ProTip!
Advisories are also available from the
GraphQL API