GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            147 advisories
        Filter by severity
        
      
      
    
                    
                      Potential XSS vulnerability in jQuery
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-11023
                      
                      was published
                        for
                        
                          components/jquery
                        
                        (RubyGems)
                      Apr 29, 2020 
                    
                  
                    
                      Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-6531
                      
                      was published
                        for
                        
                          bootstrap
                        
                        (RubyGems)
                      Jul 11, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-6484
                      
                      was published
                        for
                        
                          bootstrap
                        
                        (RubyGems)
                      Jul 11, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Withdrawn Advisory: AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-18307
                      
                      was published
                        for
                        
                          alchemy_cms
                        
                        (RubyGems)
                      May 14, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-31160
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Jul 18, 2022 
                    
                  
                    
                      Cross Site Scripting vulnerability in Contribsys Sidekiq 
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-46950
                      
                      was published
                        for
                        
                          sidekiq-unique-jobs
                        
                        (RubyGems)
                      Mar 1, 2024 
                    
                  
                    
                      Cross-site Scripting in jquery-ui
                    
                      
  Moderate
                    
                
                      
                        CVE-2010-5312
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rack-ssl Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-2538
                      
                      was published
                        for
                        
                          rack-ssl
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Possible XSS vulnerability with certain configurations of rails-html-sanitizer
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23520
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Dec 13, 2022 
                    
                  
                    
                      Possible XSS vulnerability with certain configurations of rails-html-sanitizer
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23519
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Dec 13, 2022 
                    
                  
                    
                      Potential XSS vulnerability in jQuery
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-11022
                      
                      was published
                        for
                        
                          athlon1600/youtube-downloader
                        
                        (RubyGems)
                      Apr 29, 2020 
                    
                  
                    
                      activesupport Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-3464
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-3465
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Cross site scripting in actionpack Rubygem
                    
                      
  Moderate
                    
                
                      
                        CVE-2011-1497
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Apr 22, 2022 
                    
                  
                    
                      Possible XSS Security Vulnerability in SafeBuffer#bytesplice
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-28120
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Mar 15, 2023 
                    
                  
                    
                      rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-23913
                      
                      was published
                        for
                        
                          actionview
                        
                        (RubyGems)
                      Jun 9, 2023 
                    
                  
                    
                      Decidim cross-site scripting (XSS) in the pagination
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-32469
                      
                      was published
                        for
                        
                          decidim
                        
                        (RubyGems)
                      Jul 10, 2024 
                    
                  
                    
                      decidim-meetings Cross-site scripting vulnerability in the online or hybrid meeting embeds
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-45594
                      
                      was published
                        for
                        
                          decidim-meetings
                        
                        (RubyGems)
                      Nov 13, 2024 
                    
                  
                    
                      XSS in jQuery as used in Drupal, Backdrop CMS, and other products
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-11358
                      
                      was published
                        for
                        
                          django
                        
                        (RubyGems)
                      Apr 26, 2019 
                    
                  
                    
                      OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43795
                      
                      was published
                        for
                        
                          @openc3/tool-common
                        
                        (RubyGems)
                      Oct 2, 2024 
                    
                  
                    
                      camaleon_cms affected by cross site scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-48652
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Oct 23, 2024 
                    
                  
                    
                      Cross-Site Scripting in jquery
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-7656
                      
                      was published
                        for
                        
                          jQuery
                        
                        (RubyGems)
                      May 20, 2020 
                    
                  
                    
                      Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
                    
                      
  Moderate
                    
                
                      
                        GHSA-75j2-9gmc-m855
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 25, 2024 
                    
                  
                    
                      Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
                    
                      
  Moderate
                    
                
                      
                        GHSA-8fx8-3rg2-79xw
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 23, 2024 
                    
                  
                    
                      Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)
                    
                      
  Moderate
                    
                
                      
                        GHSA-r9cr-qmfw-pmrc
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 18, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API