GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
HTML injection in JupyterLite leading to DOM Clobbering
Moderate
GHSA-gj55-2xf9-67rq
was published
for
jupyterlite-core
(pip)
Sep 6, 2024
Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context
High
CVE-2023-45815
was published
for
archivebox
(pip)
Oct 19, 2023
Django Allows Redirect via Data URL
Critical
CVE-2012-3442
was published
for
django
(pip)
May 17, 2022
Reflected cross-site scripting issue in Datasette
Moderate
CVE-2021-32670
was published
for
datasette
(pip)
Jun 7, 2021
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Moderate
CVE-2021-32797
was published
for
jupyterlab
(pip)
Aug 23, 2021
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
Moderate
CVE-2021-3988
was published
for
calibreweb
(pip)
Nov 15, 2024
OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates
Moderate
CVE-2024-49377
was published
for
OctoPrint
(pip)
Nov 5, 2024
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Moderate
CVE-2019-11358
was published
for
django
(RubyGems)
Apr 26, 2019
Lollms vulnerable to Cross-site Scripting
Moderate
CVE-2024-6581
was published
for
lollms
(pip)
Oct 29, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Moderate
CVE-2024-43795
was published
for
@openc3/tool-common
(RubyGems)
Oct 2, 2024
Streamlit publishes previously-patched Cross-site Scripting vulnerability
Moderate
CVE-2023-27494
was published
for
streamlit
(pip)
Mar 17, 2023
Roundup Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2010-2491
was published
for
roundup
(pip)
May 17, 2022
Roundup vulnerability related to Cross-site scripting (XSS)
Moderate
CVE-2008-1474
was published
for
roundup
(pip)
May 1, 2022
Cross-site scripting in recommender-xblock
Moderate
CVE-2018-20858
was published
for
recommender-xblock
(pip)
Aug 21, 2019
Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability
Moderate
CVE-2020-26249
was published
for
red-dashboard
(pip)
Dec 8, 2020
Qutebrowser XSS Vulnerability
Moderate
CVE-2018-1000559
was published
for
qutebrowser
(pip)
Sep 13, 2018
Cross-site scripting in SiCKRAGE
Moderate
CVE-2021-25925
was published
for
sickrage
(pip)
Apr 20, 2021
Cross-site Scripting in python-cjson
Moderate
CVE-2009-4924
was published
for
python-cjson
(pip)
Dec 6, 2021
Cross Site Scripting (XSS) in Quokka
Moderate
CVE-2020-18702
was published
for
quokka
(pip)
Aug 30, 2021
Cross Site Scripting (XSS) in Simiki
Moderate
CVE-2020-19000
was published
for
simiki
(pip)
Sep 1, 2021
Cross-site scripting in sickrage
Moderate
CVE-2021-25926
was published
for
sickrage
(pip)
Apr 20, 2021
Roundup Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2012-6132
was published
for
roundup
(pip)
May 17, 2022
Roundup Cross-site scripting (XSS) vulnerability
Moderate
CVE-2012-6131
was published
for
roundup
(pip)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API