GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,084 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57398
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57396
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57380
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57376
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57379
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57363
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57369
was published
Jul 13, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-57368
was published
Jul 13, 2026
The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.
High
Unreviewed
CVE-2026-57829
was published
Jul 13, 2026
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated...
High
Unreviewed
CVE-2026-61875
was published
Jul 12, 2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2026-6939
was published
Jul 11, 2026
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross...
High
Unreviewed
CVE-2026-13378
was published
Jul 11, 2026
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-13114
was published
Jul 11, 2026
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
High
CVE-2026-54070
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent...
High
Unreviewed
CVE-2026-59794
was published
Jul 10, 2026
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
High
Unreviewed
CVE-2026-59795
was published
Jul 10, 2026
The TelSender plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting in all...
High
Unreviewed
CVE-2026-15298
was published
Jul 10, 2026
The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and...
High
Unreviewed
CVE-2026-53987
was published
Jul 9, 2026
The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-9253
was published
Jul 9, 2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2026-13441
was published
Jul 9, 2026
The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2026-15000
was published
Jul 9, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19...
High
Unreviewed
CVE-2026-6896
was published
Jul 8, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7,...
High
Unreviewed
CVE-2026-13320
was published
Jul 8, 2026
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
High
CVE-2026-49825
was published
for
lxml_html_clean
(pip)
Jul 8, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
High
Unreviewed
CVE-2026-11903
was published
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API