GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,164
Erlang
30
GitHub Actions
19
Go
1,973
Maven
5,000+
npm
3,695
NuGet
654
pip
3,312
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
28,775 advisories
Filter by severity
The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some...
Moderate
Unreviewed
CVE-2022-3609
was published
Dec 12, 2022
Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute...
Moderate
Unreviewed
CVE-2022-3853
was published
Dec 12, 2022
A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could...
Moderate
Unreviewed
CVE-2022-37925
was published
Dec 12, 2022
A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a...
Moderate
Unreviewed
CVE-2022-37926
was published
Dec 12, 2022
Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5.
Moderate
Unreviewed
CVE-2021-46846
was published
Dec 12, 2022
Alist Cross-site Scripting vulnerability
Moderate
CVE-2022-45970
was published
for
github.com/alist-org/alist/v3
(Go)
Dec 12, 2022
A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is...
Moderate
Unreviewed
CVE-2022-4421
was published
Dec 12, 2022
yikes-inc-easy-mailchimp-extender Cross-site Scripting vulnerability
Moderate
CVE-2021-4244
was published
for
yikesinc/yikes-inc-easy-mailchimp-extender
(Composer)
Dec 12, 2022
Duplicate advisory: @claviska/jquery-minicolors vulnerable to Cross-site Scripting
Moderate
CVE-2021-4243
was published
for
@claviska/jquery-minicolors
(npm)
Dec 12, 2022
•
withdrawn
Stored XSS vulnerability in Jenkins Checkmarx Plugin
High
CVE-2022-46684
was published
for
com.checkmarx.jenkins:checkmarx
(Maven)
Dec 12, 2022
Cross-site Scripting in Jenkins Spring Config Plugin
High
CVE-2022-46687
was published
for
io.jenkins.plugins:spring-config
(Maven)
Dec 12, 2022
Jenkins Custom Build Properties Plugin vulnerable to Cross-site Scripting
High
CVE-2022-46686
was published
for
io.jenkins.plugins:custom-build-properties
(Maven)
Dec 12, 2022
SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller...
Moderate
Unreviewed
CVE-2022-45758
was published
Dec 12, 2022
SENS v1.0 is vulnerable to Cross Site Scripting (XSS).
Moderate
Unreviewed
CVE-2022-45756
was published
Dec 12, 2022
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to...
Moderate
Unreviewed
CVE-2022-44031
was published
Dec 12, 2022
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to...
Moderate
Unreviewed
CVE-2022-44637
was published
Dec 12, 2022
Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Moderate
Unreviewed
CVE-2022-4413
was published
Dec 12, 2022
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Moderate
Unreviewed
CVE-2022-4414
was published
Dec 12, 2022
phpMyFAQ vulnerable to Cross-site Scripting
Moderate
CVE-2022-4407
was published
for
thorsten/phpmyfaq
(Composer)
Dec 11, 2022
phpMyFAQ vulnerable to Cross-site Scripting
Moderate
CVE-2022-4408
was published
for
thorsten/phpmyfaq
(Composer)
Dec 11, 2022
A vulnerability was found in pallidlight online-course-selection-system. It has been classified...
Moderate
Unreviewed
CVE-2022-4401
was published
Dec 11, 2022
A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects...
Moderate
Unreviewed
CVE-2022-4400
was published
Dec 11, 2022
pyRdfa3 Cross-site Scripting vulnerability
Moderate
CVE-2022-4396
was published
for
pyRdfa3
(pip)
Dec 10, 2022
Yii2 Gii Cross-site Scripting vulnerability
Moderate
CVE-2022-34297
was published
for
yiisoft/yii2-gii
(Composer)
Dec 10, 2022
IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This...
Moderate
Unreviewed
CVE-2022-41299
was published
Dec 9, 2022
ProTip!
Advisories are also available from the
GraphQL API