GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,013 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52742
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52743
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52750
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52749
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52748
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52751
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52753
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-52754
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-49930
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-49953
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-49954
was published
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-49911
was published
Oct 22, 2025
Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated...
High
Unreviewed
CVE-2025-60507
was published
Oct 21, 2025
The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin...
High
Unreviewed
CVE-2020-36853
was published
Oct 18, 2025
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP...
High
Unreviewed
CVE-2025-59269
was published
Oct 15, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS)...
High
Unreviewed
CVE-2025-49552
was published
Oct 15, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
High
CVE-2025-54264
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-8459
was published
Oct 14, 2025
A Stored Cross-Site Scripting security issue exists in the affected product that could...
High
Unreviewed
CVE-2025-7329
was published
Oct 14, 2025
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server...
High
Unreviewed
CVE-2025-40772
was published
Oct 14, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release...
High
Unreviewed
CVE-2025-10552
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release...
High
Unreviewed
CVE-2025-10558
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA...
High
Unreviewed
CVE-2025-10557
was published
Oct 13, 2025
A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA...
High
Unreviewed
CVE-2025-10556
was published
Oct 13, 2025
ProTip!
Advisories are also available from the
GraphQL API