GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            306 advisories
        Filter by severity
        
      
      
    
                    
                      IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-33138
                      
                      was published
                      May 22, 2025 
                    
                  
                    
                      Froxlor has an HTML Injection Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48958
                      
                      was published
                        for
                        
                          froxlor/froxlor
                        
                        (Composer)
                      Mar 11, 2025 
                    
                  
                    
                      IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-50933
                      
                      was published
                      Feb 2, 2024 
                    
                  
                    
                      IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-51475
                      
                      was published
                      May 16, 2025 
                    
                  
                    
                      The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5686
                      
                      was published
                      Jun 6, 2025 
                    
                  
                    
                      Hax CMS Stored Cross-Site Scripting vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-49137
                      
                      was published
                        for
                        
                          elmsln/haxcms
                        
                        (Composer)
                      Jun 9, 2025 
                    
                  
                    
                      An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4278
                      
                      was published
                      Jun 12, 2025 
                    
                  
                    
                      The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4367
                      
                      was published
                      Jun 19, 2025 
                    
                  
                    
                      IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-51472
                      
                      was published
                      Jan 6, 2025 
                    
                  
                    
                      TabberNeue vulnerable to Stored XSS through wikitext
                    
                      
  High
                    
                
                      
                        CVE-2025-53093
                      
                      was published
                        for
                        
                          starcitizentools/tabber-neue
                        
                        (Composer)
                      Jun 27, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27358
                      
                      was published
                      Jul 4, 2025 
                    
                  
                    
                      SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-31326
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
                    
                      
  Critical
                    
                
                      
                        CVE-2025-53835
                      
                      was published
                        for
                        
                          org.xwiki.rendering:xwiki-rendering-syntax-xhtml
                        
                        (Maven)
                      Jul 14, 2025 
                    
                  
                    
                      IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-49343
                      
                      was published
                      Jul 28, 2025 
                    
                  
                    
                      A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20331
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8621
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-38007
                      
                      was published
                      Jun 27, 2025 
                    
                  
                    
                      IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2895
                      
                      was published
                      Jun 30, 2025 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54698
                      
                      was published
                      Aug 14, 2025 
                    
                  
                    
                      Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55672
                      
                      was published
                        for
                        
                          apache-superset
                        
                        (pip)
                      Aug 14, 2025 
                    
                  
                    
                      phpMyFAQ Vulnerable to Stored HTML Injection at FAQ
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-56199
                      
                      was published
                        for
                        
                          phpmyfaq/phpmyfaq
                        
                        (Composer)
                      Jan 2, 2025 
                    
                  
                    
                      In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57730
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-51989
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6247
                      
                      was published
                      Aug 26, 2025 
                    
                  
                    
                      A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20342
                      
                      was published
                      Aug 27, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API