GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
46 advisories
Filter by severity
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Cadwyn vulnerable to XSS on the docs page
High
CVE-2025-53528
was published
for
cadwyn
(pip)
Jul 21, 2025
ChangeDetection.io XSS in watch overview
High
CVE-2025-52558
was published
for
changedetection.io
(pip)
Jun 23, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
CVE-2025-47783
was published
for
label-studio
(pip)
May 15, 2025
Open WebUI stored cross-site scripting (XSS) vulnerability
High
CVE-2024-7990
was published
for
open-webui
(pip)
Mar 20, 2025
Open WebUI Vulnerable to a Session Fixation Attack
High
CVE-2024-7053
was published
for
open-webui
(pip)
Mar 20, 2025
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
CKAN has an XSS vector in user uploaded images in group/org and user profiles
High
CVE-2025-24372
was published
for
ckan
(pip)
Feb 5, 2025
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
High
CVE-2024-52595
was published
for
lxml-html-clean
(pip)
Nov 19, 2024
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
High
CVE-2024-43805
was published
for
jupyterlab
(pip)
Aug 29, 2024
pretix Stored Cross-site Scripting vulnerability
High
CVE-2024-8113
was published
for
pretix
(pip)
Aug 23, 2024
Sentry vulnerable to stored Cross-Site Scripting (XSS)
High
CVE-2024-41656
was published
for
sentry
(pip)
Jul 23, 2024
ansibleguy-webui Cross-site Scripting vulnerability
High
CVE-2024-36110
was published
for
ansibleguy-webui
(pip)
May 28, 2024
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
High
CVE-2024-34707
was published
for
nautobot
(pip)
May 13, 2024
pgAdmin Cross-site Scripting vulnerability in /settings/store API response json payload
High
CVE-2024-4216
was published
for
pgAdmin4
(pip)
May 2, 2024
nautobot has reflected Cross-site Scripting potential in all object list views
High
CVE-2024-32979
was published
for
nautobot
(pip)
May 1, 2024
Piccolo Admin's raw SVG loading may lead to complete data compromise from admin page
High
CVE-2024-30248
was published
for
piccolo-admin
(pip)
Apr 1, 2024
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
High
CVE-2024-28233
was published
for
jupyterhub
(pip)
Mar 28, 2024
Potentially untrusted input is rendered as HTML in final output
High
CVE-2024-26151
was published
for
mjml
(pip)
Feb 22, 2024
Cross-site Scripting in Pyhtml2pdf
High
CVE-2024-1647
was published
for
pyhtml2pdf
(pip)
Feb 20, 2024
Cross-site Scripting Vulnerability on Avatar Upload
High
CVE-2023-47115
was published
for
label-studio
(pip)
Jan 24, 2024
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
High
CVE-2024-23345
was published
for
nautobot
(pip)
Jan 23, 2024
ProTip!
Advisories are also available from the
GraphQL API