GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
421 advisories
Filter by severity
HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the...
Low
Unreviewed
CVE-2025-59854
was published
May 6, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
High
Unreviewed
CVE-2026-6002
was published
May 7, 2026
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS
Moderate
CVE-2026-28499
was published
for
github.com/vapor/leaf-kit
(Swift)
Mar 16, 2026
@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin
High
GHSA-g485-8j3v-p6x8
was published
for
@tdurieux/anonymous_github
(npm)
May 5, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in...
Moderate
Unreviewed
CVE-2023-48763
was published
Apr 24, 2024
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
Moderate
CVE-2026-40105
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 14, 2026
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a...
Moderate
Unreviewed
CVE-2026-1564
was published
Apr 16, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2023-23989
was published
Apr 24, 2024
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39841
was published
Apr 7, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39837
was published
Apr 7, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39839
was published
Apr 7, 2026
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The...
Moderate
Unreviewed
CVE-2026-26460
was published
Apr 13, 2026
A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have...
Moderate
Unreviewed
CVE-2026-20170
was published
Apr 15, 2026
Apache SkyWalking has a stored XSS vulnerability
Moderate
CVE-2025-54057
was published
for
org.apache.skywalking:apm-webapp
(Maven)
Nov 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39628
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39626
was published
Apr 8, 2026
A vulnerability has been identified in SCALANCE M-800 / S615 (All versions), SCALANCE SC-600...
Moderate
Unreviewed
CVE-2022-36325
was published
Aug 11, 2022
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39625
was published
Apr 8, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39629
was published
Apr 8, 2026
The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-15058
was published
Jan 7, 2026
The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder...
Moderate
Unreviewed
CVE-2025-3521
was published
May 1, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-39712
was published
Apr 8, 2026
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2025-66486
was published
Apr 2, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31465
was published
Mar 28, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
High
Unreviewed
CVE-2024-44061
was published
Oct 20, 2024
ProTip!
Advisories are also available from the
GraphQL API