GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,762
NuGet
678
pip
3,447
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
31,407 advisories
Filter by severity
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to...
Moderate
Unreviewed
CVE-2023-52292
was published
Jan 27, 2025
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability...
Moderate
Unreviewed
CVE-2024-37527
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-24626
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-24593
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-24708
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23457
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23531
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-23669
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23574
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23756
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23754
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23752
was published
Jan 27, 2025
A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table...
High
Unreviewed
CVE-2022-4975
was published
Jan 27, 2025
Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through...
Moderate
Unreviewed
CVE-2024-11348
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-22513
was published
Jan 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23792
was published
Jan 27, 2025
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site...
Moderate
Unreviewed
CVE-2023-46187
was published
Jan 27, 2025
A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This...
Moderate
Unreviewed
CVE-2025-0721
was published
Jan 27, 2025
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-13505
was published
Jan 26, 2025
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12334
was published
Jan 26, 2025
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected...
Moderate
Unreviewed
CVE-2024-10636
was published
Jan 26, 2025
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting....
Moderate
Unreviewed
CVE-2024-35145
was published
Jan 25, 2025
The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-0350
was published
Jan 25, 2025
The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2024-10552
was published
Jan 25, 2025
The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘zone’...
Moderate
Unreviewed
CVE-2024-11825
was published
Jan 25, 2025
ProTip!
Advisories are also available from the
GraphQL API