GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
765
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
38,986 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-67912
was published
Dec 16, 2025
Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows...
Moderate
Unreviewed
CVE-2009-2216
was published
May 2, 2022
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting ...
Moderate
Unreviewed
CVE-2022-36547
was published
Aug 27, 2022
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER,...
High
Unreviewed
CVE-2019-11193
was published
May 24, 2022
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality...
Moderate
Unreviewed
CVE-2025-65590
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68077
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68080
was published
Dec 16, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
Moderate
Unreviewed
CVE-2025-65591
was published
Dec 16, 2025
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an...
Moderate
Unreviewed
CVE-2025-36746
was published
Dec 12, 2025
Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not...
Moderate
Unreviewed
CVE-2007-1926
was published
May 1, 2022
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers...
Moderate
Unreviewed
CVE-2007-1508
was published
May 1, 2022
Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow...
Moderate
Unreviewed
CVE-2006-5983
was published
May 1, 2022
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
GHSA-wh6m-h6f4-rjf4
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables
Moderate
CVE-2025-68115
was published
for
parse-server
(npm)
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-67951
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68076
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Moderate
Unreviewed
CVE-2025-68165
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
Low
Unreviewed
CVE-2025-68163
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68079
was published
Dec 16, 2025
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed...
High
Unreviewed
CVE-2025-65778
was published
Dec 15, 2025
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page...
Moderate
Unreviewed
CVE-2025-66843
was published
Dec 15, 2025
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Moderate
Unreviewed
CVE-2025-68166
was published
Dec 16, 2025
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP...
Moderate
Unreviewed
CVE-2023-36337
was published
Dec 15, 2025
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow...
Moderate
Unreviewed
CVE-2023-53897
was published
Dec 16, 2025
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1...
Moderate
Unreviewed
CVE-2025-29231
was published
Dec 16, 2025
ProTip!
Advisories are also available from the
GraphQL API