GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,140 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56226
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56223
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56233
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56265
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56228
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56209
was published
Dec 31, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56210
was published
Dec 31, 2024
Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation (...
High
Unreviewed
CVE-2024-47925
was published
Dec 30, 2024
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
Unreviewed
CVE-2024-47917
was published
Dec 30, 2024
Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site...
High
Unreviewed
CVE-2024-47924
was published
Dec 30, 2024
Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site...
High
Unreviewed
CVE-2024-47920
was published
Dec 30, 2024
Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting...
High
Unreviewed
CVE-2024-10385
was published
Dec 20, 2024
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed...
High
Unreviewed
CVE-2024-3841
was published
Apr 17, 2024
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
High
Unreviewed
CVE-2024-47093
was published
Dec 19, 2024
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating...
High
Unreviewed
CVE-2023-23354
was published
Dec 19, 2024
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and...
High
Unreviewed
CVE-2024-56174
was published
Dec 18, 2024
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The...
High
Unreviewed
CVE-2023-6123
was published
Feb 15, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56016
was published
Dec 18, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-54350
was published
Dec 18, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-56010
was published
Dec 18, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-49677
was published
Dec 18, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-51646
was published
Dec 18, 2024
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-12024
was published
Dec 17, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-54249
was published
Dec 16, 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2024-54257
was published
Dec 16, 2024
ProTip!
Advisories are also available from the
GraphQL API