GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,126 advisories
Filter by severity
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP...
High
Unreviewed
CVE-2025-59269
was published
Oct 15, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS)...
High
Unreviewed
CVE-2025-49552
was published
Oct 15, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
High
CVE-2025-54264
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-8459
was published
Oct 14, 2025
A Stored Cross-Site Scripting security issue exists in the affected product that could...
High
Unreviewed
CVE-2025-7329
was published
Oct 14, 2025
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server...
High
Unreviewed
CVE-2025-40772
was published
Oct 14, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA...
High
Unreviewed
CVE-2025-10557
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA...
High
Unreviewed
CVE-2025-10556
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release...
High
Unreviewed
CVE-2025-10558
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release...
High
Unreviewed
CVE-2025-10552
was published
Oct 13, 2025
Bagisto is vulnerable to XSS through Admin Panel's product creation path
High
CVE-2025-60880
was published
for
bagisto/bagisto
(Composer)
Oct 10, 2025
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject...
High
Unreviewed
CVE-2025-60378
was published
Oct 10, 2025
Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized...
High
Unreviewed
CVE-2025-60869
was published
Oct 10, 2025
The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within...
High
Unreviewed
CVE-2025-11189
was published
Oct 10, 2025
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site...
High
Unreviewed
CVE-2025-25017
was published
Oct 10, 2025
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross...
High
Unreviewed
CVE-2025-25018
was published
Oct 10, 2025
Improper neutralization of input during web page generation ('cross-site scripting') in Azure...
High
Unreviewed
CVE-2025-55321
was published
Oct 9, 2025
A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a...
High
Unreviewed
CVE-2025-10240
was published
Oct 9, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via...
High
Unreviewed
CVE-2025-25009
was published
Oct 7, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2021-22291
was published
Oct 7, 2025
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server ...
High
Unreviewed
CVE-2025-60967
was published
Oct 6, 2025
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server ...
High
Unreviewed
CVE-2025-60958
was published
Oct 6, 2025
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API