GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,746
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
468 advisories
Filter by severity
Cross-Site Scripting in sanitize-html
Moderate
CVE-2017-16016
was published
for
sanitize-html
(npm)
Nov 9, 2018
Cross-Site Scripting in morris.js
Moderate
CVE-2017-16022
was published
for
morris.js
(npm)
Nov 9, 2018
Cross-Site Scripting in sanitize-html
Moderate
CVE-2017-16017
was published
for
sanitize-html
(npm)
Nov 9, 2018
Cross-Site Scripting (XSS) in restify
Moderate
CVE-2017-16018
was published
for
restify
(npm)
Nov 9, 2018
Pandao editor.md vulnerable to DOM XSS
Moderate
CVE-2018-19056
was published
for
editor.md
(npm)
Nov 9, 2018
Cross-Site Scripting in nunjucks
Moderate
CVE-2016-10547
was published
for
nunjucks
(npm)
Nov 6, 2018
XSS Filter Bypass via Encoded URL in validator
Moderate
CVE-2014-9772
was published
for
validator
(npm)
Nov 6, 2018
Stored Cross-Site Scripting in tianma-static
Moderate
CVE-2018-16474
was published
for
tianma-static
(npm)
Nov 6, 2018
No Charset in Content-Type Header in express
Moderate
CVE-2014-6393
was published
for
express
(npm)
Oct 23, 2018
Cross-Site Scripting in handlebars
Moderate
CVE-2015-8861
was published
for
handlebars
(npm)
Oct 23, 2018
Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page
Moderate
CVE-2018-18282
was published
for
next
(npm)
Oct 15, 2018
Cross-Site Scripting in sexstatic
Moderate
CVE-2018-3755
was published
for
sexstatic
(npm)
Oct 1, 2018
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14042
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14041
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
Cross-Site Scripting in exceljs
Moderate
CVE-2018-16459
was published
for
exceljs
(npm)
Sep 11, 2018
Pandao editor.md vulnerable to XSS in IMG attributes
Moderate
CVE-2018-16330
was published
for
editor.md
(npm)
Sep 6, 2018
metascraper before v5.2.0 vulnerable to stored cross-site scripting
Moderate
CVE-2018-3773
was published
for
metascraper
(npm)
Aug 8, 2018
Macro in MathJax running untrusted Javascript within a web browser
Moderate
CVE-2018-1999024
was published
for
mathjax
(npm)
Jul 27, 2018
bracket-template vulnerable to reflected XSS
Moderate
CVE-2018-3735
was published
for
bracket-template
(npm)
Jul 27, 2018
Stored Cross-Site Scripting in simplehttpserver
Moderate
CVE-2018-3716
was published
for
simplehttpserver
(npm)
Jul 26, 2018
Cross-Site Scripting in i18next
Moderate
CVE-2017-16010
was published
for
i18next
(npm)
Jul 24, 2018
ProTip!
Advisories are also available from the
GraphQL API