GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,738
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,530 advisories
Filter by severity
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1525
was published
Apr 17, 2025
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1524
was published
Apr 17, 2025
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The...
Low
Unreviewed
CVE-2024-45712
was published
Apr 15, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-3469
was published
Apr 10, 2025
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79]...
Low
Unreviewed
CVE-2025-22855
was published
Apr 8, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
CVE-2025-30166
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Apr 8, 2025
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
Low
CVE-2025-3191
was published
for
react-draft-wysiwyg
(npm)
Apr 4, 2025
Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31696
was published
for
drupal/rapidoc_elements_field_formatter
(Composer)
Apr 1, 2025
Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes
Low
CVE-2025-31697
was published
for
drupal/formatter_suite
(Composer)
Apr 1, 2025
Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31695
was published
for
drupal/link_field_display_mode_formatter
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
Low
CVE-2024-39311
was published
for
publify_core
(RubyGems)
Mar 28, 2025
SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the...
Low
Unreviewed
CVE-2025-2864
was published
Mar 28, 2025
Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW...
Low
Unreviewed
CVE-2025-27574
was published
Mar 28, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-12683
was published
Mar 26, 2025
The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings,...
Low
Unreviewed
CVE-2025-1452
was published
Mar 25, 2025
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-12769
was published
Mar 25, 2025
The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape...
Low
Unreviewed
CVE-2024-10554
was published
Mar 25, 2025
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-10560
was published
Mar 25, 2025
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which...
Low
Unreviewed
CVE-2024-13123
was published
Mar 25, 2025
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which...
Low
Unreviewed
CVE-2024-13122
was published
Mar 25, 2025
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise...
Low
Unreviewed
CVE-2025-1203
was published
Mar 24, 2025
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise...
Low
Unreviewed
CVE-2025-1062
was published
Mar 24, 2025
ProTip!
Advisories are also available from the
GraphQL API