GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,753
Erlang
35
GitHub Actions
29
Go
2,326
Maven
5,000+
npm
3,956
NuGet
712
pip
3,740
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
17 advisories
Filter by severity
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
High
Unreviewed
CVE-2025-31384
was published
Apr 4, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
High
Unreviewed
CVE-2025-22501
was published
Mar 28, 2025
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for...
High
Unreviewed
CVE-2024-13497
was published
Mar 15, 2025
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
High
Unreviewed
CVE-2024-13704
was published
Feb 18, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
High
Unreviewed
CVE-2025-24680
was published
Jan 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
High
Unreviewed
CVE-2024-44061
was published
Oct 20, 2024
The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due...
High
Unreviewed
CVE-2024-8981
was published
Oct 1, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE...
High
Unreviewed
CVE-2024-2010
was published
Sep 12, 2024
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in...
High
Unreviewed
CVE-2024-32484
was published
Jul 22, 2024
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7...
High
Unreviewed
CVE-2024-34507
was published
May 5, 2024
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar...
High
Unreviewed
CVE-2024-4439
was published
May 3, 2024
Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers...
High
Unreviewed
CVE-2024-33423
was published
May 1, 2024
A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module...
High
Unreviewed
CVE-2024-33831
was published
Apr 30, 2024
An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker...
High
Unreviewed
CVE-2023-40290
was published
Mar 27, 2024
Using an AMP url with a canonical element, an attacker could have executed JavaScript from an...
High
Unreviewed
CVE-2024-26282
was published
Feb 22, 2024
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to...
High
Unreviewed
CVE-2023-39217
was published
Aug 8, 2023
An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin...
High
Unreviewed
CVE-2022-0989
was published
Apr 12, 2022
ProTip!
Advisories are also available from the
GraphQL API