GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,942
Erlang
39
GitHub Actions
38
Go
2,599
Maven
5,000+
npm
4,249
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
29,815 advisories
Filter by severity
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try...
Moderate
Unreviewed
CVE-2025-5350
was published
Oct 24, 2025
The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12016
was published
Oct 24, 2025
The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12017
was published
Oct 24, 2025
The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-12096
was published
Oct 24, 2025
The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-10701
was published
Oct 24, 2025
The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation...
Moderate
Unreviewed
CVE-2025-9158
was published
Oct 24, 2025
Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which...
Moderate
Unreviewed
CVE-2025-58070
was published
Oct 24, 2025
Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments...
Moderate
Unreviewed
CVE-2025-61931
was published
Oct 24, 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-7730
was published
Oct 24, 2025
Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows...
Moderate
Unreviewed
CVE-2025-57240
was published
Oct 23, 2025
Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to...
Moderate
Unreviewed
CVE-2025-60859
was published
Oct 23, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting ...
Moderate
Unreviewed
CVE-2025-34512
was published
Oct 16, 2025
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user...
Moderate
Unreviewed
CVE-2024-34687
was published
May 14, 2024
Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows...
Moderate
Unreviewed
CVE-2025-56008
was published
Oct 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49932
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49933
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49929
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49934
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49928
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49923
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49927
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62060
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62042
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62058
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62024
was published
Oct 22, 2025
ProTip!
Advisories are also available from the
GraphQL API