GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,482 advisories
Filter by severity
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows...
High
Unreviewed
CVE-2025-57483
was published
Sep 29, 2025
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is...
High
Unreviewed
CVE-2025-9816
was published
Sep 27, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18...
High
Unreviewed
CVE-2025-9642
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48107
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-59012
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-4957
was published
Sep 26, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-10467
was published
Sep 25, 2025
A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can...
High
Unreviewed
CVE-2025-10244
was published
Sep 23, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-9798
was published
Sep 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-58671
was published
Sep 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-57968
was published
Sep 22, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-53692
was published
Sep 22, 2025
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint...
High
Unreviewed
CVE-2025-55888
was published
Sep 22, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-9969
was published
Sep 19, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-8411
was published
Sep 17, 2025
This vulnerability affects Firefox < 143 and Thunderbird < 143.
High
Unreviewed
CVE-2025-10534
was published
Sep 16, 2025
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows...
High
Unreviewed
CVE-2025-9826
was published
Sep 15, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47570
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47694
was published
Sep 9, 2025
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject...
High
Unreviewed
CVE-2025-45805
was published
Sep 8, 2025
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify App 1.0 allows a...
High
Unreviewed
CVE-2025-55998
was published
Sep 8, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53307
was published
Sep 5, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-58857
was published
Sep 5, 2025
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin...
High
Unreviewed
CVE-2025-57151
was published
Sep 3, 2025
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in...
High
Unreviewed
CVE-2025-57150
was published
Sep 3, 2025
ProTip!
Advisories are also available from the
GraphQL API