Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

468 advisories

Loading
CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process Moderate
CVE-2022-31175 was published for @ckeditor/ckeditor5-html-embed (npm) Aug 6, 2022
Raneto vulnerable to Cross-site Scripting Moderate
CVE-2022-35144 was published for raneto (npm) Aug 5, 2022
grapesjs before 0.19.5 vulnerable to Cross-site Scripting Moderate
CVE-2022-21802 was published for grapesjs (npm) Jul 26, 2022
markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped Moderate
CVE-2020-28455 was published for markdown-it-toc (npm) Jul 26, 2022
markdown-it-decorate vulnerable to cross-site scripting (XSS) Moderate
CVE-2020-28459 was published for markdown-it-decorate (npm) Jul 19, 2022
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label Moderate
CVE-2022-31160 was published for jQuery.UI.Combined (RubyGems) Jul 18, 2022
Elkano c960657
Borzik
Credited to Elkano, c960657, and Borzik
Angular (deprecated package) Cross-site Scripting Moderate
CVE-2022-25869 was published for angular (npm) Jul 16, 2022
Strapi 4.1.12 Cross-site Scripting via crafted file Moderate
CVE-2022-32114 was published for @strapi/strapi (npm) Jul 14, 2022
Svelte vulnerable to XSS when using objects during server-side rendering Moderate
CVE-2022-25875 was published for svelte (npm) Jul 13, 2022
Possible inject arbitrary `CSS` into the generated graph affecting the container HTML Moderate
CVE-2022-31108 was published for mermaid (npm) Jul 5, 2022
Cross site scripting in parse-url Moderate
CVE-2022-2217 was published for parse-url (npm) Jun 28, 2022
Cross site scripting in parse-url Moderate
CVE-2022-2218 was published for parse-url (npm) Jun 28, 2022
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags Moderate
CVE-2021-33295 was published for joplin (npm) Jun 17, 2022
Cross-site Scripting in NocoDB Moderate
CVE-2022-2079 was published for nocodb (npm) Jun 15, 2022
Cross-site Scripting in Strapi Moderate
CVE-2022-29894 was published for strapi (npm) Jun 14, 2022
Angular vulnerable to Cross-site Scripting Moderate
CVE-2021-4231 was published for @angular/core (npm) May 27, 2022
TTracz2i
Credited to TTracz2i
Cross-site Scripting in Bootstrap-3-Typeahead Moderate
CVE-2019-10215 was published for bassjobsen/bootstrap-3-typeahead (Composer) May 24, 2022
Cross-site Scripting in Auth0 Lock Moderate
CVE-2022-29172 was published for auth0-lock (npm) May 24, 2022
Joplin vulnerable to Cross-site Scripting in notes Moderate
CVE-2021-37916 was published for joplin (npm) May 24, 2022
Docsify vulnerable to cross-site scripting due to mishandled encoding Moderate
CVE-2021-30074 was published for docsify (npm) May 24, 2022
Formstone Vulnerable to Reflected XSS Moderate
CVE-2020-26768 was published for formstone (npm) May 24, 2022
Improper Neutralization of Input During Web Page Generation in CKEditor4 Moderate
CVE-2020-27193 was published for ckeditor4 (npm) May 24, 2022
spellman
Credited to spellman
Improper Neutralization of Input During Web Page Generation in swagger-ui Moderate
CVE-2016-1000229 was published for swagger-ui (npm) May 24, 2022
GitBook allows Cross-site Scripting via a local .md file. Moderate
CVE-2019-19596 was published for gitbook (npm) May 24, 2022
hexo-admin plugin for Node.js XSS Vulnerability Moderate
CVE-2019-17606 was published for hexo-admin (npm) May 24, 2022
ProTip! Advisories are also available from the GraphQL API