GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
516 advisories
Filter by severity
Broadleaf vulnerable to Cross-site Scripting
Moderate
CVE-2023-33725
was published
for
org.broadleafcommerce:broadleaf
(Maven)
Jun 21, 2023
Alluxio Cross Site Scripting vulnerability
Moderate
CVE-2020-21485
was published
for
org.alluxio:alluxio-parent
(Maven)
Jun 20, 2023
Stored XSS vulnerability in Jenkins Maven Repository Server Plugin
Moderate
CVE-2023-35144
was published
for
jenkins:repository
(Maven)
Jun 14, 2023
Stored XSS vulnerability in Jenkins Maven Repository Server Plugin
Moderate
CVE-2023-35143
was published
for
jenkins:repository
(Maven)
Jun 14, 2023
JStachio XSS vulnerability: Unescaped single quotes
Moderate
CVE-2023-33962
was published
for
io.jstach:jstachio
(Maven)
Jun 6, 2023
Apache JSPWiki vulnerable to cross-site scripting on several plugins
Moderate
CVE-2022-46907
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
May 25, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33944
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33937
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33940
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33938
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33941
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33939
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33943
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Cross-site scripting in Liferay Portal
Moderate
CVE-2023-33942
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
alkacon-OpenCMS vulnerable to stored Cross-site Scripting
Moderate
CVE-2023-31544
was published
for
org.opencms:opencms-core
(Maven)
May 16, 2023
Jenkins TestNG Results Plugin Stored Cross-site Scripting vulnerability
Moderate
CVE-2023-32984
was published
for
org.jenkins-ci.plugins:testng-plugin
(Maven)
May 16, 2023
ONOS vulnerable to Cross-site Scripting
Moderate
CVE-2023-30093
was published
for
org.onosproject:onos-archetypes
(Maven)
May 5, 2023
XWiki App Within Minutes app grants space admin rights that allows cross-site scripting
Moderate
CVE-2023-29515
was published
for
org.xwiki.platform:xwiki-platform-appwithinminutes
(Maven)
Apr 20, 2023
org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints
Moderate
CVE-2023-29506
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-default
(Maven)
Apr 12, 2023
XXL-JOB vulnerable to Cross-site Scripting
Moderate
CVE-2023-26120
was published
for
com.xuxueli:xxl-job
(Maven)
Apr 10, 2023
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter
Moderate
CVE-2023-29014
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments
Moderate
CVE-2023-29015
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames
Moderate
CVE-2023-29016
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Apache Archiva vulnerable to privilege escalation via stored cross-site scripting (XSS)
Moderate
CVE-2023-28158
was published
for
org.apache.archiva:archiva
(Maven)
Mar 29, 2023
ONOS vulnerable to reflected cross-site scripting
Moderate
CVE-2023-24279
was published
for
org.onosproject:onos-archetypes
(Maven)
Mar 14, 2023
ProTip!
Advisories are also available from the
GraphQL API