GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,815
Erlang
36
GitHub Actions
32
Go
2,401
Maven
5,000+
npm
4,044
NuGet
723
pip
3,830
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
36,171 advisories
Filter by severity
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site...
Moderate
Unreviewed
CVE-2025-46993
was published
Jul 24, 2025
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site...
Moderate
Unreviewed
CVE-2025-47061
was published
Jul 24, 2025
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site...
Moderate
Unreviewed
CVE-2025-46996
was published
Jul 24, 2025
A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality...
Critical
Unreviewed
CVE-2025-53084
was published
Jul 24, 2025
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter...
Critical
Unreviewed
CVE-2025-50128
was published
Jul 24, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18...
High
Unreviewed
CVE-2025-4439
was published
Jul 23, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18...
High
Unreviewed
CVE-2025-4700
was published
Jul 23, 2025
Mezzanine CMS vulnerable to Cross-site Scripting
Moderate
CVE-2025-50481
was published
for
Mezzanine
(pip)
Jul 23, 2025
A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface,...
Moderate
Unreviewed
CVE-2025-40598
was published
Jul 23, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-4411
was published
Jul 23, 2025
Harbor repository description page has Cross-site Scripting vulnerability
Moderate
CVE-2025-32019
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.
Moderate
Unreviewed
CVE-2025-54295
was published
Jul 23, 2025
A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.
High
Unreviewed
CVE-2025-54297
was published
Jul 23, 2025
A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
High
Unreviewed
CVE-2025-54296
was published
Jul 23, 2025
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored...
Moderate
Unreviewed
CVE-2025-27930
was published
Jul 23, 2025
Improper neutralization of input during web page generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-53288
was published
Jul 23, 2025
Improper neutralization of input during web page generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-53287
was published
Jul 23, 2025
The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-6261
was published
Jul 23, 2025
The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-5753
was published
Jul 23, 2025
A potential reflected cross-site scripting vulnerability has been
identified in the Poly Clariti...
Moderate
Unreviewed
CVE-2025-43484
was published
Jul 23, 2025
A potential stored cross-site scripting vulnerability has been
identified in the Poly Clariti...
Moderate
Unreviewed
CVE-2025-43486
was published
Jul 23, 2025
A potential security vulnerability has been identified in the Poly Clariti Manager for versions...
Low
Unreviewed
CVE-2025-43488
was published
Jul 23, 2025
DuraComm SPM-500 DP-10iN-100-MU
is vulnerable to a cross-site scripting attack. This could...
High
Unreviewed
CVE-2025-41425
was published
Jul 23, 2025
Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17...
Moderate
Unreviewed
CVE-2025-51462
was published
Jul 22, 2025
Aim vulnerable to Cross-site Scripting
Moderate
CVE-2025-51464
was published
for
aim
(pip)
Jul 22, 2025
ProTip!
Advisories are also available from the
GraphQL API