GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
302 advisories
Filter by severity
Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could...
High
Unreviewed
CVE-2025-15032
was published
Jan 16, 2026
A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation ...
Moderate
Unreviewed
CVE-2025-52987
was published
Jan 15, 2026
An attacker may exploit missing protection against clickjacking by tricking users into performing...
Moderate
Unreviewed
CVE-2026-22918
was published
Jan 15, 2026
PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to...
Moderate
Unreviewed
CVE-2025-65922
was published
Jan 5, 2026
Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature
Low
GHSA-24v3-254g-jv85
was published
for
@tutao/tutanota-utils
(npm)
Dec 19, 2025
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address...
High
Unreviewed
CVE-2025-14809
was published
Dec 19, 2025
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar...
High
Unreviewed
CVE-2025-14812
was published
Dec 19, 2025
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI...
Moderate
Unreviewed
CVE-2025-59479
was published
Dec 16, 2025
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110...
Moderate
Unreviewed
CVE-2025-14373
was published
Dec 12, 2025
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an...
High
Unreviewed
CVE-2025-48639
was published
Dec 8, 2025
In multiple locations, there is a possible way to trick a user into accepting a permission due to...
High
Unreviewed
CVE-2025-48597
was published
Dec 8, 2025
FeehiCMS is vulnerable to reverse tabnabbing
Moderate
CVE-2025-63522
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking...
Moderate
Unreviewed
CVE-2025-36149
was published
Nov 21, 2025
This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen...
High
Unreviewed
CVE-2025-13132
was published
Nov 21, 2025
Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software...
Moderate
Unreviewed
CVE-2025-0421
was published
Nov 19, 2025
The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack,...
Moderate
Unreviewed
CVE-2025-64387
was published
Oct 31, 2025
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to...
Moderate
Unreviewed
CVE-2025-30191
was published
Oct 31, 2025
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An...
Moderate
Unreviewed
CVE-2024-30109
was published
Oct 30, 2025
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
Moderate
Unreviewed
CVE-2025-28129
was published
Oct 6, 2025
HCL MyXalytics
6.6. product is affected by Use of Vulnerable/Outdated Versions Vulnerability
Low
Unreviewed
CVE-2025-52658
was published
Oct 3, 2025
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the...
High
Unreviewed
CVE-2025-32350
was published
Sep 4, 2025
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay...
High
Unreviewed
CVE-2025-32349
was published
Sep 4, 2025
Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows...
Moderate
Unreviewed
CVE-2024-13066
was published
Sep 3, 2025
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack...
Low
Unreviewed
CVE-2025-41000
was published
Sep 3, 2025
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the...
Moderate
Unreviewed
CVE-2025-1494
was published
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API