GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
149 advisories
Filter by severity
A vulnerability in the web-based management interface of Cisco Integrated Management Controller ...
Moderate
Unreviewed
CVE-2023-20228
was published
Aug 16, 2023
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly...
Moderate
Unreviewed
CVE-2023-20179
was published
Sep 27, 2023
phpMyFAQ vulnerable to stored XSS on attachments filename
Moderate
CVE-2024-24574
was published
for
phpmyfaq/phpmyfaq
(Composer)
Feb 5, 2024
An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16...
Moderate
Unreviewed
CVE-2023-5933
was published
Jan 26, 2024
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that...
Moderate
Unreviewed
CVE-2023-25833
was published
Jul 6, 2023
Apache Tomcat XSS Vulnerability
Moderate
CVE-2006-7195
was published
for
org.apache.tomcat:tomcat
(Maven)
May 1, 2022
Jetty Javascript Inclusion Vulnerability
Moderate
CVE-2002-1533
was published
for
org.mortbay.jetty:jetty
(Maven)
Apr 30, 2022
hexo-theme-anzhiyu Cross-site Scripting vulnerability
Moderate
CVE-2024-25865
was published
for
hexo-theme-anzhiyu
(npm)
Mar 3, 2024
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users...
Moderate
Unreviewed
CVE-2024-1606
was published
Mar 18, 2024
phpMyFAQ Stored HTML Injection at contentLink
Moderate
CVE-2024-28108
was published
for
phpmyfaq/phpmyfaq
(Composer)
Mar 25, 2024
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been...
Moderate
Unreviewed
CVE-2008-10001
was published
Mar 29, 2022
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in ISS BlackICE PC Protection. It has...
Moderate
Unreviewed
CVE-2003-5003
was published
Mar 29, 2022
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042,...
Moderate
Unreviewed
CVE-2024-20362
was published
Apr 3, 2024
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1...
Moderate
Unreviewed
CVE-2019-6577
was published
May 24, 2022
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions ...
Moderate
Unreviewed
CVE-2019-10933
was published
May 24, 2022
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The...
Moderate
Unreviewed
CVE-2019-1010018
was published
May 24, 2022
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized...
Moderate
Unreviewed
CVE-2023-29112
was published
Apr 11, 2023
The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101,...
Moderate
Unreviewed
CVE-2023-29110
was published
Apr 11, 2023
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in...
Moderate
Unreviewed
CVE-2022-35850
was published
Apr 11, 2023
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device...
Moderate
Unreviewed
CVE-2023-24496
was published
Jul 6, 2023
Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device...
Moderate
Unreviewed
CVE-2023-24497
was published
Jul 6, 2023
There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and...
Moderate
Unreviewed
CVE-2022-38210
was published
Jul 6, 2023
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter...
Moderate
Unreviewed
CVE-2023-1384
was published
Jul 6, 2023
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama...
Moderate
Unreviewed
CVE-2023-0007
was published
Jul 6, 2023
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
Moderate
Unreviewed
CVE-2023-23548
was published
Aug 1, 2023
ProTip!
Advisories are also available from the
GraphQL API