GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,951
Erlang
39
GitHub Actions
38
Go
2,607
Maven
5,000+
npm
4,251
NuGet
757
pip
4,017
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,515 advisories
Filter by severity
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered....
High
Unreviewed
CVE-2025-54301
was published
Aug 25, 2025
A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of...
High
Unreviewed
CVE-2025-5352
was published
Aug 23, 2025
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
High
Unreviewed
CVE-2025-55573
was published
Aug 22, 2025
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6....
High
Unreviewed
CVE-2025-55420
was published
Aug 21, 2025
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the...
High
Unreviewed
CVE-2025-51991
was published
Aug 20, 2025
In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
High
Unreviewed
CVE-2025-57731
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54055
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54056
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54670
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54027
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54032
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-54044
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53559
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53563
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53562
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53201
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53205
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53212
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53226
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53319
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-53564
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48168
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48163
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48296
was published
Aug 20, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-48297
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API