GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
259 advisories
Filter by severity
Mattermost Server is vulnerable to XSS through author_link field in Slack attachments
Moderate
CVE-2017-18879
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows XSS via CSRF
Moderate
CVE-2016-11084
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through crafted links
Moderate
CVE-2016-11082
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows XSS via redirect URL
Moderate
CVE-2016-11079
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
Moderate
CVE-2016-11083
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through customizable theme color-code values
Moderate
CVE-2016-11070
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
Moderate
CVE-2016-11071
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS via a Legal or Support setting
Moderate
CVE-2016-11073
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server vulnerable to Cross-site Scripting through file preview feature
Moderate
CVE-2016-11063
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Grafana XSS via a column style
Moderate
CVE-2018-18624
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Grafana XSS via the OpenTSDB datasource
Moderate
CVE-2020-13430
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Grafana XSS in header column rename
Moderate
CVE-2020-12245
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Gophish XSS Vulnerability
Moderate
CVE-2019-16146
was published
for
github.com/gophish/gophish
(Go)
May 24, 2022
Gitea XSS Vulnerability
Moderate
CVE-2019-1010261
was published
for
code.gitea.io/gitea
(Go)
May 24, 2022
Gitea XSS Vulnerability in Repository Description
Moderate
CVE-2019-1010314
was published
for
code.gitea.io/gitea
(Go)
May 24, 2022
Grafana Cross-site Scripting vulnerability
Moderate
CVE-2019-13068
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Grafana XSS Vulnerability
Moderate
CVE-2018-1000816
was published
for
github.com/grafana/grafana
(Go)
May 14, 2022
Hydra has Reflected XSS via error_hint parameter
Moderate
CVE-2019-8400
was published
for
github.com/ory/hydra
(Go)
May 14, 2022
Woodpecker allows cross-site scripting (XSS) via build logs
Moderate
CVE-2022-29947
was published
for
github.com/woodpecker-ci/woodpecker
(Go)
Apr 30, 2022
Cross-site Scripting in Alist
Moderate
CVE-2022-26533
was published
for
github.com/Xhofe/alist
(Go)
Mar 13, 2022
Cross-site Scripting in Gitea
Moderate
CVE-2021-45329
was published
for
github.com/go-gitea/gitea
(Go)
Feb 10, 2022
Subdomain Takeover in Interactsh server
Moderate
CVE-2023-36474
was published
for
github.com/projectdiscovery/interactsh
(Go)
Jan 27, 2022
Unsafe inline XSS in pasting DOM element into chat
High
CVE-2021-39183
was published
for
github.com/owncast/owncast
(Go)
Dec 14, 2021
Cross-site Scripting in github.com/schollz/rwtxt
Moderate
CVE-2021-20848
was published
for
github.com/schollz/rwtxt
(Go)
Nov 29, 2021
ProTip!
Advisories are also available from the
GraphQL API