GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
197 advisories
Filter by severity
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco...
Moderate
Unreviewed
CVE-2025-20342
was published
Aug 27, 2025
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-6247
was published
Aug 26, 2025
HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster...
High
Unreviewed
CVE-2025-51989
was published
Aug 21, 2025
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
Moderate
Unreviewed
CVE-2025-57730
was published
Aug 20, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-54698
was published
Aug 14, 2025
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1...
Moderate
Unreviewed
CVE-2025-2895
was published
Jun 30, 2025
IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6...
Moderate
Unreviewed
CVE-2023-38007
was published
Jun 27, 2025
The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c...
Moderate
Unreviewed
CVE-2025-8621
was published
Aug 12, 2025
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow...
Moderate
Unreviewed
CVE-2025-20331
was published
Aug 6, 2025
IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker...
Moderate
Unreviewed
CVE-2024-49343
was published
Jul 28, 2025
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This...
High
Unreviewed
CVE-2025-8029
was published
Jul 22, 2025
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML...
Moderate
Unreviewed
CVE-2025-31326
was published
Jul 8, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-27358
was published
Jul 4, 2025
IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0...
Low
Unreviewed
CVE-2024-51472
was published
Jan 6, 2025
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-4367
was published
Jun 19, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18...
High
Unreviewed
CVE-2025-4278
was published
Jun 12, 2025
The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-5686
was published
Jun 6, 2025
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote...
Moderate
Unreviewed
CVE-2024-51475
was published
May 16, 2025
IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject...
Moderate
Unreviewed
CVE-2023-50933
was published
Feb 2, 2024
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2025-33138
was published
May 22, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2023-46310
was published
Jun 4, 2024
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ...
Moderate
Unreviewed
CVE-2025-23393
was published
May 27, 2025
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE)...
Moderate
Unreviewed
CVE-2025-20267
was published
May 21, 2025
The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-4126
was published
May 15, 2025
The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
Moderate
Unreviewed
CVE-2025-4168
was published
May 3, 2025
ProTip!
Advisories are also available from the
GraphQL API