GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
428 advisories
Filter by severity
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a...
Moderate
Unreviewed
CVE-2026-1564
was published
Apr 16, 2026
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have...
Moderate
Unreviewed
CVE-2026-20170
was published
Apr 15, 2026
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
Moderate
CVE-2026-40105
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 14, 2026
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The...
Moderate
Unreviewed
CVE-2026-26460
was published
Apr 13, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39712
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39628
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39629
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39626
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39625
was published
Apr 8, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39839
was published
Apr 7, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39841
was published
Apr 7, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39837
was published
Apr 7, 2026
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2025-66486
was published
Apr 2, 2026
An attacker might be able to inject HTML content into the internal web dashboard by sending...
Low
Unreviewed
CVE-2026-0396
was published
Mar 31, 2026
The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-1834
was published
Mar 31, 2026
Home Assistant has stored XSS in Map-card through malicious device name
Low
CVE-2026-33044
was published
for
homeassistant
(pip)
Mar 27, 2026
OpenBao has Reflected XSS in its OIDC authentication error message
Critical
CVE-2026-33758
was published
for
github.com/openbao/openbao
(Go)
Mar 26, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9...
High
Unreviewed
CVE-2026-2995
was published
Mar 25, 2026
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
High
GHSA-5vp3-3cg6-2rq3
was published
for
justhtml
(pip)
Mar 24, 2026
The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI
Moderate
CVE-2026-4267
was published
for
johnbillion/query-monitor
(Composer)
Mar 19, 2026
Filament Unvalidated Range and Values summarizer values can be used for XSS
High
CVE-2026-33080
was published
for
filament/tables
(Composer)
Mar 18, 2026
XSS in @leanprover/unicode-input-component
Low
CVE-2026-32732
was published
for
@leanprover/unicode-input-component
(npm)
Mar 16, 2026
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS
Moderate
CVE-2026-28499
was published
for
github.com/vapor/leaf-kit
(Swift)
Mar 16, 2026
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security...
Moderate
Unreviewed
CVE-2026-20070
was published
Mar 4, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-28132
was published
Feb 26, 2026
ProTip!
Advisories are also available from the
GraphQL API