GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,965
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
34,119 advisories
Filter by severity
Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability...
Moderate
Unreviewed
CVE-2013-10071
was published
Oct 31, 2025
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the...
Moderate
Unreviewed
CVE-2011-10036
was published
Oct 31, 2025
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the...
Moderate
Unreviewed
CVE-2011-10037
was published
Oct 31, 2025
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert...
Moderate
Unreviewed
CVE-2011-10039
was published
Oct 31, 2025
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link...
Moderate
Unreviewed
CVE-2011-10040
was published
Oct 31, 2025
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the...
Moderate
Unreviewed
CVE-2011-10038
was published
Oct 31, 2025
Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows...
Moderate
Unreviewed
CVE-2025-52180
was published
Oct 30, 2025
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint...
Moderate
Unreviewed
CVE-2025-56313
was published
Oct 30, 2025
An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975...
Moderate
Unreviewed
CVE-2025-60950
was published
Oct 30, 2025
A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to...
Moderate
Unreviewed
CVE-2025-63885
was published
Oct 30, 2025
Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28,...
Moderate
Unreviewed
CVE-2025-36592
was published
Oct 30, 2025
Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-5347
was published
Oct 30, 2025
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-5343
was published
Oct 30, 2025
URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a...
Moderate
Unreviewed
CVE-2025-10348
was published
Oct 30, 2025
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-12475
was published
Oct 30, 2025
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs...
Moderate
Unreviewed
CVE-2025-12450
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64289
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64291
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64197
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64204
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64200
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64208
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64220
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64194
was published
Oct 29, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64202
was published
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API