GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
29,187 advisories
Filter by severity
Cross-Site Scripting in Wagtail
Moderate
CVE-2020-15118
was published
for
wagtail
(pip)
Jul 20, 2020
Cross-Site Scripting in semantic-ui-search
High
GHSA-p9vv-3945-x93h
was published
for
semantic-ui-search
(npm)
Sep 2, 2020
Cross-Site Scripting in bpmn-js-properties-panel
High
GHSA-vpj4-89q8-rh38
was published
for
bpmn-js-properties-panel
(npm)
Sep 3, 2020
Cross-Site Scripting in cmmn-js-properties-panel
High
GHSA-vmh4-322v-cfpc
was published
for
cmmn-js-properties-panel
(npm)
Sep 3, 2020
Cross Site Scripting and RCE in baserCMS
Low
CVE-2020-15159
was published
for
baserproject/basercms
(Composer)
Aug 28, 2020
Cross Site Scripting in baserCMS
Low
CVE-2020-15154
was published
for
baserproject/basercms
(Composer)
Aug 28, 2020
methodOverride Middleware Reflected Cross-Site Scripting in connect
Low
CVE-2013-7370
was published
for
connect
(npm)
Aug 31, 2020
Cross-Site Scripting in fomantic-ui
High
GHSA-788m-pj96-7w2c
was published
for
fomantic-ui
(npm)
Sep 2, 2020
Cross-Site Scripting in google-closure-library
Moderate
GHSA-r9q4-w3fm-wrm2
was published
for
google-closure-library
(npm)
Sep 2, 2020
Cross-Site Scripting in swagger-ui
Moderate
GHSA-388g-jwpg-x6j4
was published
for
swagger-ui
(npm)
Sep 11, 2020
Cross-Site Scripting in swagger-ui
Moderate
GHSA-w992-2gmj-9xxj
was published
for
swagger-ui
(npm)
Sep 11, 2020
Cross-Site Scripting in serve
Moderate
GHSA-cpgr-wmr9-qxv4
was published
for
serve
(npm)
Sep 11, 2020
Cross-Site Scripting in takeapeek
High
GHSA-4q2f-8g74-qm56
was published
for
takeapeek
(npm)
Sep 3, 2020
Cross-Site Scripting in hexo-admin
High
GHSA-phph-xpj4-wvcv
was published
for
hexo-admin
(npm)
Sep 3, 2020
XSS in client rendered block templates in rendr
High
CVE-2016-1000230
was published
for
rendr
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
Moderate
GHSA-vp93-gcx5-4w52
was published
for
swagger-ui
(npm)
Sep 11, 2020
Cross-Site Scripting in atlasboard-atlassian-package
High
GHSA-25v4-mcx4-hh35
was published
for
atlasboard-atlassian-package
(npm)
Sep 4, 2020
Reflected Cross-Site Scripting in redis-commander
Low
GHSA-8c8c-4vfj-rrpc
was published
for
redis-commander
(npm)
Sep 1, 2020
HTML Injection in marky-markdown
High
GHSA-mg69-6j3m-jvgw
was published
for
marky-markdown
(npm)
Sep 3, 2020
Cross-Site Scripting in bootstrap-select
High
GHSA-9r7h-6639-v5mw
was published
for
bootstrap-select
(npm)
Sep 3, 2020
Cross-Site Scripting in mermaid
High
GHSA-w32g-5hqp-gg6q
was published
for
mermaid
(npm)
Sep 2, 2020
Edit feed settings and others, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0
Low
CVE-2020-15273
was published
for
baserproject/basercms
(Composer)
Nov 4, 2020
Cross-Site Scripting in scratch-svg-renderer
High
CVE-2020-7750
was published
for
scratch-svg-renderer
(npm)
Nov 9, 2020
ProTip!
Advisories are also available from the
GraphQL API