GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
330 advisories
Filter by severity
Argo CD allows cross-site scripting on repositories page
Critical
CVE-2025-47933
was published
for
github.com/argoproj/argo-cd
(Go)
May 28, 2025
Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advance...
Critical
Unreviewed
CVE-2024-10865
was published
May 14, 2025
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS)...
Critical
Unreviewed
CVE-2025-43567
was published
May 13, 2025
org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content
Critical
CVE-2025-46558
was published
for
org.xwiki.contrib.markdown:syntax-markdown-commonmark12
(Maven)
Apr 30, 2025
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into...
Critical
Unreviewed
CVE-2025-24297
was published
Apr 16, 2025
pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering
Critical
CVE-2025-2946
was published
for
pgadmin4
(pip)
Apr 3, 2025
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Critical
CVE-2025-30223
was published
for
github.com/beego/beego
(Go)
Mar 31, 2025
An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the...
Critical
Unreviewed
CVE-2024-8017
was published
Mar 20, 2025
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML...
Critical
Unreviewed
CVE-2024-39272
was published
Feb 6, 2025
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists...
Critical
Unreviewed
CVE-2024-57428
was published
Feb 6, 2025
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Critical
CVE-2025-24981
was published
for
@nuxtjs/mdc
(npm)
Feb 6, 2025
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
Critical
GHSA-9x4v-xfq5-m8x5
was published
for
better-auth
(npm)
Feb 5, 2025
Software installed and run as a non-privileged user may conduct improper GPU system calls to...
Critical
Unreviewed
CVE-2024-47891
was published
Jan 31, 2025
The specific component in Celk Saude 3.1.252.1 that processes user input and returns error...
Critical
Unreviewed
CVE-2024-48761
was published
Jan 30, 2025
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in...
Critical
Unreviewed
CVE-2024-57686
was published
Jan 10, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in...
Critical
Unreviewed
CVE-2024-12626
was published
Dec 19, 2024
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The...
Critical
Unreviewed
CVE-2024-12641
was published
Dec 16, 2024
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a...
Critical
Unreviewed
CVE-2024-11986
was published
Dec 13, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting ...
Critical
Unreviewed
CVE-2024-54032
was published
Dec 10, 2024
whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.
Critical
Unreviewed
CVE-2024-53442
was published
Dec 5, 2024
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to...
Critical
Unreviewed
CVE-2024-6516
was published
Dec 5, 2024
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot...
Critical
Unreviewed
CVE-2024-49038
was published
Nov 26, 2024
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0...
Critical
Unreviewed
CVE-2024-51053
was published
Nov 18, 2024
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service...
Critical
Unreviewed
CVE-2023-43091
was published
Nov 17, 2024
XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in...
Critical
Unreviewed
CVE-2024-10217
was published
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API