GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
371 advisories
Filter by severity
usememos/memos Cross-site Scripting vulnerability
Critical
CVE-2022-4865
was published
for
github.com/usememos/memos
(Go)
Dec 31, 2022
usememos/memos vulnerable to Cross-site Scripting
Critical
CVE-2022-4866
was published
for
github.com/usememos/memos
(Go)
Dec 31, 2022
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are...
Critical
Unreviewed
CVE-2018-18864
was published
May 14, 2022
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute...
Critical
Unreviewed
CVE-2022-43143
was published
Nov 21, 2022
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored...
Critical
Unreviewed
CVE-2022-46332
was published
Dec 6, 2022
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this...
Critical
Unreviewed
CVE-2019-7551
was published
May 13, 2022
An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to...
Critical
Unreviewed
CVE-2018-19222
was published
May 13, 2022
A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An...
Critical
Unreviewed
CVE-2018-10369
was published
May 13, 2022
Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an...
Critical
Unreviewed
CVE-2022-34322
was published
Jan 1, 2023
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering...
Critical
Unreviewed
CVE-2019-3709
was published
May 13, 2022
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an...
Critical
Unreviewed
CVE-2019-3708
was published
May 13, 2022
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the...
Critical
Unreviewed
CVE-2017-8898
was published
May 13, 2022
Unsafe defaults in `remark-html`
Critical
CVE-2021-39199
was published
for
remark-html
(npm)
Sep 7, 2021
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries...
Critical
Unreviewed
CVE-2018-9079
was published
May 13, 2022
XSS vulnerability with translator
Critical
CVE-2021-32671
was published
for
flarum/core
(Composer)
Jun 7, 2021
XSS Cross Site Scripting
Critical
CVE-2021-29459
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 22, 2021
Cross-site Scripting (XSS) in Eclipse Theia
Critical
CVE-2020-27224
was published
for
@theia/preview
(npm)
Apr 13, 2021
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user...
Critical
Unreviewed
CVE-2022-40288
was published
Nov 1, 2022
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS)...
Critical
Unreviewed
CVE-2022-40287
was published
Nov 1, 2022
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the...
Critical
Unreviewed
CVE-2022-40289
was published
Nov 1, 2022
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18...
Critical
Unreviewed
CVE-2022-1575
was published
May 6, 2022
Cross site scripting vulnerability with discussion titles
Critical
CVE-2022-41938
was published
for
flarum/core
(Composer)
Nov 21, 2022
XSS via prototype pollution in NodeBB
Critical
CVE-2021-43787
was published
for
nodebb
(npm)
Nov 30, 2021
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo...
Critical
Unreviewed
CVE-2022-28712
was published
Aug 23, 2022
The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable...
Critical
Unreviewed
CVE-2022-30577
was published
Sep 22, 2022
ProTip!
Advisories are also available from the
GraphQL API