GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,885
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,212
NuGet
744
pip
3,988
Pub
12
RubyGems
950
Rust
1,038
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,954 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2021-22291
was published
Oct 7, 2025
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via...
High
Unreviewed
CVE-2025-25009
was published
Oct 7, 2025
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server ...
High
Unreviewed
CVE-2025-60967
was published
Oct 6, 2025
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server ...
High
Unreviewed
CVE-2025-60958
was published
Oct 6, 2025
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
High
GHSA-wq95-wr7m-26h4
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application....
High
Unreviewed
CVE-2025-52653
was published
Oct 3, 2025
A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7...
High
Unreviewed
CVE-2025-60991
was published
Oct 1, 2025
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337...
High
Unreviewed
CVE-2025-57393
was published
Oct 1, 2025
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within...
High
Unreviewed
CVE-2025-57424
was published
Sep 29, 2025
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows...
High
Unreviewed
CVE-2025-57483
was published
Sep 29, 2025
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is...
High
Unreviewed
CVE-2025-9816
was published
Sep 27, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18...
High
Unreviewed
CVE-2025-9642
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48107
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-59012
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-4957
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-10467
was published
Sep 25, 2025
Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
High
CVE-2025-59839
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 24, 2025
A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can...
High
Unreviewed
CVE-2025-10244
was published
Sep 23, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-9798
was published
Sep 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-58671
was published
Sep 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-57968
was published
Sep 22, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-53692
was published
Sep 22, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint...
High
Unreviewed
CVE-2025-55888
was published
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API