GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,318
Maven
5,000+
npm
3,950
NuGet
711
pip
3,730
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
30,316 advisories
Filter by severity
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock,...
Moderate
Unreviewed
CVE-2023-32595
was published
Aug 25, 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup...
Moderate
Unreviewed
CVE-2023-24394
was published
Aug 25, 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page...
Moderate
Unreviewed
CVE-2023-32575
was published
Aug 25, 2023
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form...
Moderate
Unreviewed
CVE-2023-25981
was published
Aug 25, 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion...
Moderate
Unreviewed
CVE-2023-32518
was published
Aug 25, 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain...
Moderate
Unreviewed
CVE-2023-32591
was published
Aug 25, 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in John Newcombe eBecas plugin <=...
Moderate
Unreviewed
CVE-2023-32584
was published
Aug 25, 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eji Osigwe DevBuddy Twitter...
Moderate
Unreviewed
CVE-2023-32577
was published
Aug 25, 2023
Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store...
Moderate
Unreviewed
CVE-2023-32576
was published
Aug 25, 2023
A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7...
Moderate
Unreviewed
CVE-2023-38974
was published
Aug 25, 2023
A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows...
Moderate
Unreviewed
CVE-2023-38973
was published
Aug 25, 2023
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2023-4520
was published
Aug 25, 2023
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2023-39700
was published
Aug 25, 2023
@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content
Moderate
CVE-2023-41167
was published
for
@webiny/react-rich-text-renderer
(npm)
Aug 24, 2023
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2023-40875
was published
Aug 24, 2023
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2023-40877
was published
Aug 24, 2023
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2023-40876
was published
Aug 24, 2023
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2023-40874
was published
Aug 24, 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts...
Moderate
Unreviewed
CVE-2023-32510
was published
Aug 24, 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro...
Moderate
Unreviewed
CVE-2023-32511
was published
Aug 24, 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food...
Moderate
Unreviewed
CVE-2023-32516
was published
Aug 24, 2023
Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management...
Moderate
Unreviewed
CVE-2023-36317
was published
Aug 24, 2023
Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint
Moderate
CVE-2023-40577
was published
for
github.com/prometheus/alertmanager
(Go)
Aug 23, 2023
SilverStripe CMS Cross-site Scripting vulnerabilities inherited from TinyMCE
Moderate
GHSA-jxcx-3h54-qqxx
was published
for
silverstripe/admin
(Composer)
Aug 23, 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for...
Moderate
Unreviewed
CVE-2023-32119
was published
Aug 23, 2023
ProTip!
Advisories are also available from the
GraphQL API