GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
289 advisories
Filter by severity
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to...
Critical
Unreviewed
CVE-2022-1344
was published
Apr 14, 2022
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows...
Critical
Unreviewed
CVE-2022-1346
was published
Apr 14, 2022
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs...
Critical
Unreviewed
CVE-2021-32157
was published
Apr 12, 2022
Remote code injection in dompdf/dompdf
Critical
CVE-2022-28368
was published
for
dompdf/dompdf
(Composer)
Apr 4, 2022
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Critical
Unreviewed
CVE-2022-25620
was published
Mar 31, 2022
Arbitrary code execution in post-loader
Critical
CVE-2022-0748
was published
for
post-loader
(npm)
Mar 18, 2022
Cross-site Scripting in showdoc/showdoc
Critical
CVE-2022-0960
was published
for
showdoc/showdoc
(Composer)
Mar 15, 2022
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling...
Critical
Unreviewed
CVE-2021-44749
was published
Mar 7, 2022
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability...
Critical
Unreviewed
CVE-2022-25069
was published
Mar 6, 2022
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross...
Critical
Unreviewed
CVE-2022-25395
was published
Mar 4, 2022
A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool...
Critical
Unreviewed
CVE-2021-42940
was published
Feb 12, 2022
Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated...
Critical
Unreviewed
CVE-2022-21241
was published
Feb 9, 2022
BeyondTrust Secure Remote Access Base Software through 6.0.1 allows an attacker to achieve full...
Critical
Unreviewed
CVE-2021-31589
was published
Feb 8, 2022
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26,...
Critical
Unreviewed
CVE-2021-24814
was published
Feb 8, 2022
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This...
Critical
Unreviewed
CVE-2022-24123
was published
Jan 31, 2022
/usr/local/www/pkg.php in pfSense through 2.5.2 uses $_REQUEST['pkg_filter'] in a PHP echo call.
Critical
Unreviewed
CVE-2022-23993
was published
Jan 27, 2022
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using...
Critical
Unreviewed
CVE-2021-40909
was published
Jan 25, 2022
The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add...
Critical
Unreviewed
CVE-2022-22769
was published
Jan 20, 2022
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The ...
Critical
Unreviewed
CVE-2022-22114
was published
Jan 11, 2022
In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the...
Critical
Unreviewed
CVE-2022-22115
was published
Jan 11, 2022
XSS via prototype pollution in NodeBB
Critical
CVE-2021-43787
was published
for
nodebb
(npm)
Nov 30, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
CVE-2021-41132
was published
for
omero-figure
(pip)
Oct 14, 2021
SQL Injection and Cross-site Scripting in class-validator
Critical
CVE-2019-18413
was published
for
class-validator
(npm)
Oct 12, 2021
Unsafe defaults in `remark-html`
Critical
CVE-2021-39199
was published
for
remark-html
(npm)
Sep 7, 2021
Dolibarr Cross-site Scripting vulnerability
Critical
CVE-2021-25955
was published
for
dolibarr/dolibarr
(Composer)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API