GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            38,081 advisories
        Filter by severity
        
      
      
    
                    
                      The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11806
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Log Server versions prior to 2024R1 contain a stored cross-site scripting (XSS)...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-58272
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-14001
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS)...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34278
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-14000
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7314
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7321
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7318
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS)...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-13993
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7316
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7319
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7312
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7313
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7323
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-7315
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-53690
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-50588
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-47697
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-47696
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-47689
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-50584
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS)...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-53689
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-47694
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-50586
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.7 / Nagios XI 5.8.9 contains...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-50585
                      
                      was published
                      Oct 31, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API