GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
378 advisories
Filter by severity
Indico vulnerable to Cross-Site Scripting via LaTeX math code
Moderate
CVE-2025-59035
was published
for
indico
(pip)
Sep 10, 2025
copyparty vulnerable to reflected cross-site scripting via k304 parameter
Moderate
CVE-2023-38501
was published
for
copyparty
(pip)
Jul 25, 2023
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
copyparty Reflected XSS via Filter Parameter
Moderate
CVE-2025-54589
was published
for
copyparty
(pip)
Jul 31, 2025
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
Moderate
CVE-2025-54423
was published
for
copyparty
(pip)
Jul 28, 2025
Mezzanine CMS vulnerable to Cross-site Scripting
Moderate
CVE-2025-50481
was published
for
Mezzanine
(pip)
Jul 23, 2025
Cadwyn vulnerable to XSS on the docs page
High
CVE-2025-53528
was published
for
cadwyn
(pip)
Jul 21, 2025
Aim vulnerable to Cross-site Scripting
Moderate
CVE-2025-51464
was published
for
aim
(pip)
Jul 22, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function
Moderate
CVE-2025-6050
was published
for
Mezzanine
(pip)
Jun 17, 2025
Roundup is vulnerable to XSS through interactions between URLs and issue tracker templates
Moderate
CVE-2025-53865
was published
for
roundup
(pip)
Jul 13, 2025
Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality
Moderate
CVE-2024-53999
was published
for
mobsf
(pip)
Dec 3, 2024
ChangeDetection.io XSS in watch overview
High
CVE-2025-52558
was published
for
changedetection.io
(pip)
Jun 23, 2025
Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
Moderate
CVE-2024-26152
was published
for
label-studio
(pip)
Feb 22, 2024
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
CVE-2025-47783
was published
for
label-studio
(pip)
May 15, 2025
Mezzanine CMS Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-29573
was published
for
Mezzanine
(pip)
May 5, 2025
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Moderate
CVE-2025-46335
was published
for
mobsf
(pip)
May 5, 2025
Web2py Reflected XSS vulnerability
Moderate
CVE-2016-4807
was published
for
web2py
(pip)
May 17, 2022
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
Moderate
CVE-2014-0157
was published
for
horizon
(pip)
May 14, 2022
Roundup Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2012-6130
was published
for
roundup
(pip)
May 17, 2022
plone.namedfile vulnerable to Stored Cross Site Scripting with SVG images
Low
CVE-2023-41048
was published
for
plone.namedfile
(pip)
Sep 21, 2023
MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
Critical
CVE-2024-27133
was published
for
mlflow
(pip)
Feb 24, 2024
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering
Critical
CVE-2025-2946
was published
for
pgadmin4
(pip)
Apr 3, 2025
ProTip!
Advisories are also available from the
GraphQL API