GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,638
Erlang
34
GitHub Actions
26
Go
2,249
Maven
5,000+
npm
3,903
NuGet
702
pip
3,671
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
33,891 advisories
Filter by severity
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to...
Moderate
Unreviewed
CVE-2025-29513
was published
Apr 18, 2025
A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by...
Moderate
Unreviewed
CVE-2025-3788
was published
Apr 18, 2025
A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by...
Moderate
Unreviewed
CVE-2025-3789
was published
Apr 18, 2025
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG...
Moderate
Unreviewed
CVE-2025-3056
was published
Apr 18, 2025
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-3106
was published
Apr 18, 2025
The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-3598
was published
Apr 18, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39469
was published
Apr 18, 2025
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-13650
was published
Apr 18, 2025
The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for...
Moderate
Unreviewed
CVE-2025-2613
was published
Apr 18, 2025
A Stored cross-site scripting (XSS)
vulnerability in upnp page of the web Interface in TP-Link...
High
Unreviewed
CVE-2025-25427
was published
Apr 18, 2025
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-3246
was published
Apr 18, 2025
Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.
Moderate
Unreviewed
CVE-2024-40124
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39558
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39567
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-39562
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39594
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39464
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39519
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39521
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39432
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-39444
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39420
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-39428
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-39427
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-32674
was published
Apr 17, 2025
ProTip!
Advisories are also available from the
GraphQL API