GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
428 advisories
Filter by severity
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in ISS BlackICE PC Protection. It has...
Moderate
Unreviewed
CVE-2003-5003
was published
Mar 29, 2022
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042,...
Moderate
Unreviewed
CVE-2024-20362
was published
Apr 3, 2024
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1...
Moderate
Unreviewed
CVE-2019-6577
was published
May 24, 2022
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions ...
Moderate
Unreviewed
CVE-2019-10933
was published
May 24, 2022
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The...
Moderate
Unreviewed
CVE-2019-1010018
was published
May 24, 2022
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The...
Critical
Unreviewed
CVE-2019-13923
was published
May 24, 2022
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized...
Moderate
Unreviewed
CVE-2023-29112
was published
Apr 11, 2023
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101,...
Moderate
Unreviewed
CVE-2023-29110
was published
Apr 11, 2023
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in...
Moderate
Unreviewed
CVE-2022-35850
was published
Apr 11, 2023
There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and...
Moderate
Unreviewed
CVE-2022-38210
was published
Jul 6, 2023
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter...
Moderate
Unreviewed
CVE-2023-1384
was published
Jul 6, 2023
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama...
Moderate
Unreviewed
CVE-2023-0007
was published
Jul 6, 2023
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
Moderate
Unreviewed
CVE-2023-23548
was published
Aug 1, 2023
The Ninja Forms WordPress Ninja Forms Contact Form WordPress plugin before 3.6.26 was affected by...
Moderate
Unreviewed
CVE-2023-4109
was published
Aug 30, 2023
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows...
Moderate
Unreviewed
CVE-2023-3971
was published
Oct 4, 2023
An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet...
Moderate
Unreviewed
CVE-2023-36555
was published
Oct 10, 2023
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and...
Moderate
Unreviewed
CVE-2019-25144
was published
Jun 7, 2023
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
Moderate
Unreviewed
CVE-2023-22309
was published
Apr 20, 2023
static-web-server vulnerable to stored Cross-site Scripting in directory listings via file names
Moderate
CVE-2024-32966
was published
for
static-web-server
(Rust)
May 1, 2024
Blind XSS Leading to Froxlor Application Compromise
Critical
CVE-2024-34070
was published
for
froxlor/froxlor
(Composer)
May 10, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2024-24874
was published
May 17, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2024-32790
was published
May 17, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in...
Low
Unreviewed
CVE-2024-4214
was published
May 17, 2024
phpxmlrpc/extra XSS in class documenting_xmlrpc_server
Moderate
GHSA-ww6p-q26w-fr6m
was published
for
phpxmlrpc/extras
(Composer)
May 20, 2024
teler-waf subject to Bypass of Common Web Attack Threat Rule with HTML Entities Payload
Moderate
CVE-2023-26046
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
ProTip!
Advisories are also available from the
GraphQL API