GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
XSS in Mapfish Print relating to JSONP support
Low
CVE-2020-15231
was published
for
org.mapfish.print:print-lib
(Maven)
Jul 7, 2020
Cross-site Scripting in Wildfly
Low
CVE-2021-3536
was published
for
org.wildfly:wildfly-parent
(Maven)
May 25, 2021
Cross-site scripting in Apache Syncome EndUser
Low
CVE-2019-17557
was published
for
org.apache.syncope.client:syncope-client-enduser
(Maven)
Jan 6, 2022
Alkacon OpenCms XSS via username during login
Low
CVE-2005-4294
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Cross-site scripting in Apache Struts
Low
CVE-2006-1548
was published
for
struts:struts
(Maven)
May 1, 2022
Alkacon OpenCms XSS via query parameter in a search action
Low
CVE-2006-2571
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCms XSS via unsanitized message body
Low
CVE-2006-3933
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Apache Tomcat XSS In Accept-Language Headers
Low
CVE-2007-1358
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Apache Tomcat vulnerable to Cross-site Scripting
Low
CVE-2007-2450
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via file tree navigation in system/workplace/views/explorer/tree_files.jsp
Low
CVE-2008-1045
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon Open CMS XSS via Logfile Viewer Settings function
Low
CVE-2008-1300
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via searchfilter or listSearchFilter parameter
Low
CVE-2008-1510
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS XSS via searchfilter parameter in system/workplace/admin/workplace/sessions.jsp
Low
CVE-2008-1753
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Cross-site scripting in Apache ActiveMQ
Low
CVE-2010-0684
was published
for
org.apache.activemq:activemq-parent
(Maven)
May 2, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2012-0324
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 4, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2012-0325
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 4, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2015-5326
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2012-6074
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Alkacon OpenCMS XSS via homelink, workplaceresource, mode and query parameters
Low
CVE-2015-2351
was published
for
org.opencms:opencms-core
(Maven)
May 14, 2022
Jenkins allows Cross-Site Scripting (XSS) in User Configuration
Low
CVE-2013-5573
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins Build Failure Analyzer Plugin allows Cross-Site Scripting (XSS)
Low
CVE-2013-6374
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 17, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2015-1813
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2011-4344
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Alkacon OpenCMS XSS via title and requestedResource parameters
Low
CVE-2013-4600
was published
for
org.opencms:opencms-core
(Maven)
May 17, 2022
Cross-site Scripting in Apache Struts
Low
CVE-2011-1772
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API