GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
56 advisories
Filter by severity
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Low
GHSA-h5jc-78hr-3pc9
was published
for
@sveltia/cms
(npm)
Jun 19, 2026
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
Low
CVE-2026-53724
was published
for
parse-server
(npm)
Jun 19, 2026
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Low
CVE-2026-54326
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 16, 2026
Cross-site scripting via <NoScript> slot content in Nuxt's head components
Low
GHSA-m3q2-p4fw-w38m
was published
for
nuxt
(npm)
Jun 16, 2026
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
Low
CVE-2026-65900
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
Low
CVE-2026-65901
was published
for
dompurify
(npm)
Jun 15, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML
Low
GHSA-97r8-rf7q-wmjw
was published
for
@sveltia/cms
(npm)
May 18, 2026
Astro: Server island encrypted parameters vulnerable to cross-component replay
Low
CVE-2026-45028
was published
for
astro
(npm)
May 13, 2026
DbGate has cross site scripting via the SVG Icon String Handler component
Low
CVE-2026-6216
was published
for
dbgate-web
(npm)
Apr 13, 2026
unhead: Streaming SSR `streamKey` injected into inline script without identifier validation
Low
GHSA-x7mm-9vvv-64w8
was published
for
unhead
(npm)
Apr 10, 2026
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
CVE-2026-47099
was published
for
telejson
(npm)
Apr 2, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Low
GHSA-7q9x-8g6p-3x75
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
Low
CVE-2026-31873
was published
for
unhead
(npm)
Mar 12, 2026
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Low
CVE-2026-30830
was published
for
defuddle
(npm)
Mar 6, 2026
OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation
Low
CVE-2026-32040
was published
for
openclaw
(npm)
Mar 3, 2026
mailparser vulnerable to Cross-site Scripting
Low
CVE-2026-3455
was published
for
mailparser
(npm)
Mar 3, 2026
Quill is vulnerable to XSS via HTML export feature
Low
CVE-2025-15056
was published
for
quill
(npm)
Jan 13, 2026
QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting
Low
CVE-2026-0824
was published
for
@questdb/web-console
(npm)
Jan 10, 2026
Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature
Low
GHSA-24v3-254g-jv85
was published
for
@tutao/tutanota-utils
(npm)
Dec 19, 2025
Orejime has executable code in HTML attributes
Low
CVE-2025-68457
was published
for
orejime
(npm)
Dec 19, 2025
ProTip!
Advisories are also available from the
GraphQL API