Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

38,007 advisories

Loading
Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax Moderate
CVE-2025-62798 was published for code16/sharp (Composer) Oct 29, 2025
robyfirnandoyusuf aguingand
Credited to robyfirnandoyusuf and aguingand
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64289 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64291 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64208 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64204 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64200 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64202 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64197 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64220 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Unknown Unreviewed
CVE-2025-64194 was published Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Moderate Unreviewed
CVE-2025-49042 was published Oct 29, 2025
PrivateBin is missing HTML sanitization of attached filename in file size hint Moderate
CVE-2025-62796 was published for privatebin/privatebin (Composer) Oct 28, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS High
CVE-2025-59837 was published for astro (npm) Oct 28, 2025
everping GeneralZero
Credited to everping and GeneralZero
ProTip! Advisories are also available from the GraphQL API