GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,744
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
468 advisories
Filter by severity
CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process
Moderate
CVE-2022-31175
was published
for
@ckeditor/ckeditor5-html-embed
(npm)
Aug 6, 2022
Raneto vulnerable to Cross-site Scripting
Moderate
CVE-2022-35144
was published
for
raneto
(npm)
Aug 5, 2022
grapesjs before 0.19.5 vulnerable to Cross-site Scripting
Moderate
CVE-2022-21802
was published
for
grapesjs
(npm)
Jul 26, 2022
markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped
Moderate
CVE-2020-28455
was published
for
markdown-it-toc
(npm)
Jul 26, 2022
markdown-it-decorate vulnerable to cross-site scripting (XSS)
Moderate
CVE-2020-28459
was published
for
markdown-it-decorate
(npm)
Jul 19, 2022
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
Moderate
CVE-2022-31160
was published
for
jQuery.UI.Combined
(RubyGems)
Jul 18, 2022
Angular (deprecated package) Cross-site Scripting
Moderate
CVE-2022-25869
was published
for
angular
(npm)
Jul 16, 2022
Strapi 4.1.12 Cross-site Scripting via crafted file
Moderate
CVE-2022-32114
was published
for
@strapi/strapi
(npm)
Jul 14, 2022
Svelte vulnerable to XSS when using objects during server-side rendering
Moderate
CVE-2022-25875
was published
for
svelte
(npm)
Jul 13, 2022
Possible inject arbitrary `CSS` into the generated graph affecting the container HTML
Moderate
CVE-2022-31108
was published
for
mermaid
(npm)
Jul 5, 2022
Cross site scripting in parse-url
Moderate
CVE-2022-2217
was published
for
parse-url
(npm)
Jun 28, 2022
Cross site scripting in parse-url
Moderate
CVE-2022-2218
was published
for
parse-url
(npm)
Jun 28, 2022
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags
Moderate
CVE-2021-33295
was published
for
joplin
(npm)
Jun 17, 2022
Angular vulnerable to Cross-site Scripting
Moderate
CVE-2021-4231
was published
for
@angular/core
(npm)
May 27, 2022
Cross-site Scripting in Bootstrap-3-Typeahead
Moderate
CVE-2019-10215
was published
for
bassjobsen/bootstrap-3-typeahead
(Composer)
May 24, 2022
Cross-site Scripting in Auth0 Lock
Moderate
CVE-2022-29172
was published
for
auth0-lock
(npm)
May 24, 2022
Joplin vulnerable to Cross-site Scripting in notes
Moderate
CVE-2021-37916
was published
for
joplin
(npm)
May 24, 2022
Docsify vulnerable to cross-site scripting due to mishandled encoding
Moderate
CVE-2021-30074
was published
for
docsify
(npm)
May 24, 2022
Formstone Vulnerable to Reflected XSS
Moderate
CVE-2020-26768
was published
for
formstone
(npm)
May 24, 2022
Improper Neutralization of Input During Web Page Generation in CKEditor4
Moderate
CVE-2020-27193
was published
for
ckeditor4
(npm)
May 24, 2022
Improper Neutralization of Input During Web Page Generation in swagger-ui
Moderate
CVE-2016-1000229
was published
for
swagger-ui
(npm)
May 24, 2022
GitBook allows Cross-site Scripting via a local .md file.
Moderate
CVE-2019-19596
was published
for
gitbook
(npm)
May 24, 2022
hexo-admin plugin for Node.js XSS Vulnerability
Moderate
CVE-2019-17606
was published
for
hexo-admin
(npm)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API