GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,092 advisories
Filter by severity
The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2025-1294
was published
Apr 25, 2025
Insufficient URI protocol whitelist in HCL Leap
allows script injection through query parameters.
High
Unreviewed
CVE-2023-37534
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46499
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46502
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46449
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46478
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46234
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39397
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39408
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39400
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39382
was published
Apr 24, 2025
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2767
was published
Apr 23, 2025
The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
High
Unreviewed
CVE-2025-3809
was published
Apr 19, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39469
was published
Apr 18, 2025
A Stored cross-site scripting (XSS)
vulnerability in upnp page of the web Interface in TP-Link...
High
Unreviewed
CVE-2025-25427
was published
Apr 18, 2025
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-3246
was published
Apr 18, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39558
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39567
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39594
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39432
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39519
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39464
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39521
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-39420
was published
Apr 17, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-32674
was published
Apr 17, 2025
ProTip!
Advisories are also available from the
GraphQL API