GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,838
Erlang
36
GitHub Actions
33
Go
2,460
Maven
5,000+
npm
4,082
NuGet
723
pip
3,873
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
213 advisories
Filter by severity
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-39524
was published
Apr 16, 2025
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a...
Moderate
Unreviewed
CVE-2025-0272
was published
Apr 3, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-32230
was published
Apr 10, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-32200
was published
Apr 4, 2025
Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default),...
Moderate
Unreviewed
CVE-2006-0149
was published
May 1, 2022
Leantime affected by Improper Neutralization of HTML Tags
Moderate
CVE-2025-28254
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Duplicate Advisory: Leantime affected by Improper Neutralization of HTML Tags
Moderate
GHSA-jf6p-4hgv-v6qh
was published
for
leantime/leantime
(Composer)
Mar 28, 2025
•
withdrawn
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31604
was published
Mar 31, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31575
was published
Mar 31, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31075
was published
Mar 28, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-31465
was published
Mar 28, 2025
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and...
Moderate
Unreviewed
CVE-2025-1997
was published
Mar 27, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29426
was published
Mar 17, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29427
was published
Mar 17, 2025
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise...
Moderate
Unreviewed
CVE-2025-25363
was published
Mar 13, 2025
A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User...
Moderate
Unreviewed
CVE-2025-28015
was published
Mar 13, 2025
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting ...
Moderate
Unreviewed
CVE-2025-29430
was published
Mar 17, 2025
Formwork has a cross-site scripting (XSS) vulnerability in Site title
Moderate
GHSA-vf6x-59hh-332f
was published
for
getformwork/formwork
(Composer)
Mar 1, 2025
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject...
Moderate
Unreviewed
CVE-2023-35006
was published
Jul 10, 2024
VMware Cloud Director Availability contains an HTML injection vulnerability.
A
malicious actor...
Moderate
Unreviewed
CVE-2024-22277
was published
Jul 4, 2024
An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML...
Moderate
Unreviewed
CVE-2024-34398
was published
Mar 12, 2025
In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
Moderate
CVE-2025-27155
was published
for
github.com/matrix-org/pinecone
(Go)
Mar 4, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
is vulnerable to HTML injection, caused...
Moderate
Unreviewed
CVE-2024-49337
was published
Feb 20, 2025
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to HTML injection. A remote attacker...
Moderate
Unreviewed
CVE-2024-38318
was published
Feb 6, 2025
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2024-35112
was published
Jan 25, 2025
ProTip!
Advisories are also available from the
GraphQL API