GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            15 advisories
        Filter by severity
        
      
      
    
                    
                      Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2018-3740
                      
                      was published
                        for
                        
                          sanitize
                        
                        (RubyGems)
                      Mar 21, 2018 
                    
                  
                    
                      Cross-site Scripting in Sanitize 
                    
                      
  High
                    
                
                      
                        CVE-2020-4054
                      
                      was published
                        for
                        
                          sanitize
                        
                        (RubyGems)
                      Jun 16, 2020 
                    
                  
                    
                      Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in view_component
                    
                      
  High
                    
                
                      
                        CVE-2022-24722
                      
                      was published
                        for
                        
                          view_component
                        
                        (RubyGems)
                      Mar 2, 2022 
                    
                  
                    
                      Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Pay
                    
                      
  High
                    
                
                      
                        CVE-2023-30614
                      
                      was published
                        for
                        
                          pay
                        
                        (RubyGems)
                      Apr 20, 2023 
                    
                  
                    
                      sidekiq vulnerable to cross-site scripting 
                    
                      
  High
                    
                
                      
                        CVE-2023-1892
                      
                      was published
                        for
                        
                          sidekiq
                        
                        (RubyGems)
                      Apr 21, 2023 
                    
                  
                    
                      avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
                    
                      
  High
                    
                
                      
                        CVE-2023-34103
                      
                      was published
                        for
                        
                          avo
                        
                        (RubyGems)
                      Jun 6, 2023 
                    
                  
                    
                      Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
                    
                      
  High
                    
                
                      
                        CVE-2023-36823
                      
                      was published
                        for
                        
                          sanitize
                        
                        (RubyGems)
                      Jul 6, 2023 
                    
                  
                    
                      Decidim Cross-site Scripting vulnerability in the processes filter
                    
                      
  High
                    
                
                      
                        CVE-2023-34089
                      
                      was published
                        for
                        
                          decidim
                        
                        (RubyGems)
                      Jul 11, 2023 
                    
                  
                    
                      avo vulnerable to stored cross-site scripting (XSS) in key_value field
                    
                      
  High
                    
                
                      
                        CVE-2024-22191
                      
                      was published
                        for
                        
                          avo
                        
                        (RubyGems)
                      Jan 16, 2024 
                    
                  
                    
                      XSS sidekiq-unique-jobs UI server vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-25122
                      
                      was published
                        for
                        
                          sidekiq-unique-jobs
                        
                        (RubyGems)
                      Feb 13, 2024 
                    
                  
                    
                      Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
                    
                      
  High
                    
                
                      
                        CVE-2024-28199
                      
                      was published
                        for
                        
                          phlex
                        
                        (RubyGems)
                      Mar 12, 2024 
                    
                  
                    
                      Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
                    
                      
  High
                    
                
                      
                        CVE-2024-32463
                      
                      was published
                        for
                        
                          phlex
                        
                        (RubyGems)
                      Apr 17, 2024 
                    
                  
                    
                      Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
                    
                      
  High
                    
                
                      
                        CVE-2024-32970
                      
                      was published
                        for
                        
                          phlex
                        
                        (RubyGems)
                      May 1, 2024 
                    
                  
                    
                      activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
                    
                      
  High
                    
                
                      
                        CVE-2024-37031
                      
                      was published
                        for
                        
                          activeadmin
                        
                        (RubyGems)
                      Jun 2, 2024 
                    
                  
                    
                      Decidim has a cross-site scripting vulnerability in the version control page
                    
                      
  High
                    
                
                      
                        CVE-2024-41673
                      
                      was published
                        for
                        
                          decidim
                        
                        (RubyGems)
                      Oct 1, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API