GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
623 advisories
Filter by severity
VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-29271
was published
for
vvvebjs
(npm)
Mar 22, 2024
Cross-site scripting in Survey Creator
Moderate
CVE-2024-28635
was published
for
survey-creator
(npm)
Mar 21, 2024
RSSHub Cross-site Scripting vulnerability caused by internal media proxy
Moderate
CVE-2024-27926
was published
for
rsshub
(npm)
Mar 6, 2024
hexo-theme-anzhiyu Cross-site Scripting vulnerability
Moderate
CVE-2024-25865
was published
for
hexo-theme-anzhiyu
(npm)
Mar 3, 2024
Cross-site Scripting in electron-pdf
High
CVE-2024-1648
was published
for
electron-pdf
(npm)
Feb 20, 2024
Cross-site Scripting in Serenity
Moderate
CVE-2024-26318
was published
for
@serenity-is/corelib
(npm)
Feb 19, 2024
Ghost has possible Cross-site Scripting issue
Moderate
CVE-2024-23724
was published
for
ghost
(npm)
Feb 11, 2024
CKEditor cross-site scripting vulnerability in AJAX sample
Moderate
CVE-2023-4771
was published
for
ckeditor4
(npm)
Feb 7, 2024
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
Moderate
CVE-2024-24816
was published
for
ckeditor4
(npm)
Feb 7, 2024
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
Moderate
CVE-2024-24815
was published
for
ckeditor/ckeditor
(Composer)
Feb 7, 2024
Stimulsoft Dashboard.JS Cross Site Scripting vulnerability
Moderate
CVE-2024-24396
was published
for
stimulsoft-dashboards-js
(npm)
Feb 5, 2024
Stimulsoft Dashboard.JS Cross Site Scripting vulnerability
Moderate
CVE-2024-24397
was published
for
stimulsoft-dashboards-js
(npm)
Feb 5, 2024
Dash apps vulnerable to Cross-site Scripting
Moderate
CVE-2024-21485
was published
for
dash
(npm)
Feb 2, 2024
@urql/next Cross-site Scripting vulnerability
High
CVE-2024-24556
was published
for
@urql/next
(npm)
Jan 30, 2024
react-query-streamed-hydration Cross-site Scripting vulnerability
High
CVE-2024-24558
was published
for
@tanstack/react-query-next-experimental
(npm)
Jan 30, 2024
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE
Moderate
GHSA-gjhc-6xm7-mc8q
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE
Moderate
GHSA-q5pp-5q2h-g8rv
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE plugins
Moderate
GHSA-wxj2-777f-vxmf
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Layui cross-site scripting (XSS) vulnerability
Moderate
CVE-2023-50550
was published
for
layui
(npm)
Dec 30, 2023
Cross-site Scripting in @spscommerce/ds-react
Critical
GHSA-cfxh-frx4-9gjg
was published
for
@spscommerce/ds-react
(npm)
Dec 15, 2023
Cross-site Scripting in evershop
Moderate
CVE-2023-46495
was published
for
@evershop/evershop
(npm)
Dec 8, 2023
Cross Site Scripting in evershop
Moderate
CVE-2023-46494
was published
for
@evershop/evershop
(npm)
Dec 8, 2023
Cross-site Scripting in evershop
Moderate
CVE-2023-46499
was published
for
@evershop/evershop
(npm)
Dec 8, 2023
Vite XSS vulnerability in `server.transformIndexHtml` via URL payload
Moderate
CVE-2023-49293
was published
for
vite
(npm)
Dec 5, 2023
ProTip!
Advisories are also available from the
GraphQL API