GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
332 advisories
Filter by severity
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD...
Critical
Unreviewed
CVE-2023-3526
was published
Aug 8, 2023
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2023-36217
was published
Aug 3, 2023
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2...
Critical
Unreviewed
CVE-2022-46733
was published
Jul 6, 2023
SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting ...
Critical
Unreviewed
CVE-2022-40190
was published
Jul 6, 2023
Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet...
Critical
Unreviewed
CVE-2023-30321
was published
Jul 6, 2023
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker...
Critical
Unreviewed
CVE-2023-34192
was published
Jul 6, 2023
Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java...
Critical
Unreviewed
CVE-2023-30320
was published
Jul 6, 2023
Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java...
Critical
Unreviewed
CVE-2023-30319
was published
Jul 6, 2023
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can...
Critical
Unreviewed
CVE-2022-45938
was published
Jun 2, 2023
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker...
Critical
Unreviewed
CVE-2023-28347
was published
May 31, 2023
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to...
Critical
Unreviewed
CVE-2023-21516
was published
May 27, 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management...
Critical
Unreviewed
CVE-2023-31703
was published
May 17, 2023
An improper neutralization of input during web page generation ('Cross-site Scripting')...
Critical
Unreviewed
CVE-2023-22637
was published
May 4, 2023
Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote...
Critical
Unreviewed
CVE-2021-29996
was published
May 24, 2022
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The...
Critical
Unreviewed
CVE-2019-13923
was published
May 24, 2022
A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service...
Critical
Unreviewed
CVE-2019-5397
was published
May 24, 2022
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would...
Critical
Unreviewed
CVE-2019-3873
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** Leostream Connection Broker 8.2.x is affected by stored XSS. An...
Critical
Unreviewed
CVE-2020-26574
was published
May 24, 2022
Cross Site Scripting vulnerability in Axigen WebMail v.10.5.7 and before allows a remote attacker...
Critical
Unreviewed
CVE-2023-48974
was published
Feb 8, 2024
Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting
Critical
CVE-2024-25601
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 21, 2024
Liferay Portal and Liferay DXP's Users Admin module vulnerable to stored Cross-site Scripting
Critical
CVE-2024-25602
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 21, 2024
Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
Critical
CVE-2024-25147
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 21, 2024
Liferay Portal Message Board widget and Liferay DXP vulnerable to stored Cross-site Scripting
Critical
CVE-2024-25152
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 21, 2024
Liferay Portal stored cross-site scripting (XSS) vulnerability
Critical
CVE-2024-25145
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 7, 2024
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro...
Critical
Unreviewed
CVE-2024-24594
was published
Feb 6, 2024
ProTip!
Advisories are also available from the
GraphQL API