GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,891
Erlang
37
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,221
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
292 advisories
Filter by severity
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could...
Moderate
Unreviewed
CVE-2025-31992
was published
Oct 12, 2025
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2025-10496
was published
Oct 9, 2025
A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.
Moderate
Unreviewed
CVE-2025-52654
was published
Oct 3, 2025
The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in...
Moderate
Unreviewed
CVE-2025-11241
was published
Oct 3, 2025
The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-10128
was published
Sep 30, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-60100
was published
Sep 26, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-59573
was published
Sep 22, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-57928
was published
Sep 22, 2025
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-10125
was published
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco...
Moderate
Unreviewed
CVE-2025-20342
was published
Aug 27, 2025
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-6247
was published
Aug 26, 2025
HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster...
High
Unreviewed
CVE-2025-51989
was published
Aug 21, 2025
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
Moderate
Unreviewed
CVE-2025-57730
was published
Aug 20, 2025
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-55672
was published
for
apache-superset
(pip)
Aug 14, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-54698
was published
Aug 14, 2025
The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c...
Moderate
Unreviewed
CVE-2025-8621
was published
Aug 12, 2025
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow...
Moderate
Unreviewed
CVE-2025-20331
was published
Aug 6, 2025
IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker...
Moderate
Unreviewed
CVE-2024-49343
was published
Jul 28, 2025
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This...
High
Unreviewed
CVE-2025-8029
was published
Jul 22, 2025
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
Critical
CVE-2025-53835
was published
for
org.xwiki.rendering:xwiki-rendering-syntax-xhtml
(Maven)
Jul 14, 2025
SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML...
Moderate
Unreviewed
CVE-2025-31326
was published
Jul 8, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-27358
was published
Jul 4, 2025
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1...
Moderate
Unreviewed
CVE-2025-2895
was published
Jun 30, 2025
TabberNeue vulnerable to Stored XSS through wikitext
High
CVE-2025-53093
was published
for
starcitizentools/tabber-neue
(Composer)
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API