GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
31,227 advisories
Filter by severity
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator...
Moderate
Unreviewed
CVE-2023-6801
was published
Jan 6, 2024
Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform...
Moderate
Unreviewed
CVE-2023-50609
was published
Jan 6, 2024
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the...
Moderate
Unreviewed
CVE-2023-47559
was published
Jan 5, 2024
A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This...
Moderate
Unreviewed
CVE-2024-0246
was published
Jan 5, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-52125
was published
Jan 5, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-52124
was published
Jan 5, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-52178
was published
Jan 5, 2024
OCSInventory allow stored email template with special characters that lead to a Stored cross-site...
Moderate
Unreviewed
CVE-2023-3726
was published
Jan 4, 2024
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce...
Moderate
Unreviewed
CVE-2023-7044
was published
Jan 4, 2024
Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to...
Moderate
Unreviewed
CVE-2023-50630
was published
Jan 4, 2024
ecrire/public/assembler.php in SPIP before 4.1.3 and 4.2.x before 4.2.7 allows XSS because input...
Moderate
Unreviewed
CVE-2023-52322
was published
Jan 4, 2024
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2023-6738
was published
Jan 4, 2024
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2023-6498
was published
Jan 4, 2024
When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed...
High
Unreviewed
CVE-2023-5880
was published
Jan 3, 2024
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
Moderate
Unreviewed
CVE-2023-50092
was published
Jan 3, 2024
The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before...
Moderate
Unreviewed
CVE-2023-6621
was published
Jan 3, 2024
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2023-6747
was published
Jan 3, 2024
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any...
Moderate
Unreviewed
CVE-2023-6986
was published
Jan 3, 2024
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress...
Moderate
Unreviewed
CVE-2023-6629
was published
Jan 3, 2024
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin...
Moderate
Unreviewed
CVE-2023-6980
was published
Jan 3, 2024
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress...
High
Unreviewed
CVE-2023-7027
was published
Jan 3, 2024
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2023-6524
was published
Jan 3, 2024
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2023-6600
was published
Jan 3, 2024
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as...
Moderate
Unreviewed
CVE-2024-0190
was published
Jan 2, 2024
A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as...
Moderate
Unreviewed
CVE-2024-0189
was published
Jan 2, 2024
ProTip!
Advisories are also available from the
GraphQL API