GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
713 advisories
Filter by severity
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2026-16633
was published
for
pdfjs-dist
(npm)
Aug 6, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
High
CVE-2026-70492
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
High
CVE-2026-69151
was published
for
@angular/compiler
(npm)
Aug 3, 2026
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
High
CVE-2026-69149
was published
for
@angular/platform-server
(npm)
Aug 3, 2026
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
High
CVE-2026-53608
was published
for
@apostrophecms/seo
(npm)
Jul 31, 2026
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
High
CVE-2026-58263
was published
for
jodit
(npm)
Jul 31, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
Open WebUI: Stored web worker XSS via Pyodide
High
CVE-2026-59214
was published
for
open-webui
(pip)
Jul 24, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
High
GHSA-gx64-gj6p-pc4c
was published
for
jupyterlab
(pip)
Jul 22, 2026
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
CVE-2026-65592
was published
for
n8n
(npm)
Jul 22, 2026
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
CVE-2026-65597
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
GHSA-vhcw-f978-xjjg
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
GHSA-h5xr-fqvj-253p
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
ViewComponent: around_render HTML-Safety Bypass
High
CVE-2026-54498
was published
for
view_component
(RubyGems)
Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php
High
CVE-2026-62944
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
High
CVE-2026-54087
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 14, 2026
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
High
CVE-2026-54064
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
CVE-2026-49259
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
NukeViet: Unauthenticated Reflected XSS in Comment Module
High
CVE-2026-48118
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
High
CVE-2026-54070
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
High
CVE-2026-49825
was published
for
lxml_html_clean
(pip)
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API