GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            306 advisories
        Filter by severity
        
      
      
    
                    
                      Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-39663
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53883
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-36121
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62936
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62897
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11823
                      
                      was published
                      Oct 25, 2025 
                    
                  
                    
                      The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11992
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58970
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      bagisto has Cross Site Scripting (XSS) in Create New Customer
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62414
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62418
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62415
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11161
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11160
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability.  An attacker could...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-31992
                      
                      was published
                      Oct 12, 2025 
                    
                  
                    
                      The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10496
                      
                      was published
                      Oct 9, 2025 
                    
                  
                    
                      A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52654
                      
                      was published
                      Oct 3, 2025 
                    
                  
                    
                      The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11241
                      
                      was published
                      Oct 3, 2025 
                    
                  
                    
                      The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10128
                      
                      was published
                      Sep 30, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60100
                      
                      was published
                      Sep 26, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59573
                      
                      was published
                      Sep 22, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57928
                      
                      was published
                      Sep 22, 2025 
                    
                  
                    
                      The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10125
                      
                      was published
                      Sep 17, 2025 
                    
                  
                    
                      listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
                    
                      
  High
                    
                
                      
                        CVE-2025-58430
                      
                      was published
                        for
                        
                          github.com/knadh/listmonk
                        
                        (Go)
                      Sep 9, 2025 
                    
                  
                    
                      A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20342
                      
                      was published
                      Aug 27, 2025 
                    
                  
                    
                      The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6247
                      
                      was published
                      Aug 26, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API