GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,879
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
446 advisories
Filter by severity
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103584
was published
Oct 1, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103585
was published
Oct 1, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103437
was published
Sep 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103438
was published
Sep 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103439
was published
Sep 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103445
was published
Sep 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103443
was published
Sep 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Low
Unreviewed
CVE-2026-103444
was published
Sep 30, 2026
Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
Low
CVE-2026-97711
was published
for
serialize-javascript
(npm)
Sep 30, 2026
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
Low
Unreviewed
CVE-2026-27085
was published
Sep 30, 2026
Laravel: XSS in Debug Page Information
Low
CVE-2026-102279
was published
for
laravel/framework
(Composer)
Sep 29, 2026
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
High
CVE-2026-57440
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 25, 2026
Home Assistant: XSS in Statistics Graph Card
Critical
CVE-2026-91130
was published
for
homeassistant
(pip)
Sep 22, 2026
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2026-12751
was published
Sep 15, 2026
Apache Spark History Server allows stored cross-site scripting through unescaped application names
Moderate
CVE-2026-32773
was published
for
org.apache.spark:spark-core_2.12
(Maven)
Sep 2, 2026
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Moderate
CVE-2026-55696
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-5218
was published
Aug 27, 2026
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown()...
Moderate
Unreviewed
CVE-2026-5389
was published
Aug 23, 2026
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000...
Moderate
Unreviewed
CVE-2026-20232
was published
Aug 19, 2026
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows...
Moderate
Unreviewed
CVE-2026-75872
was published
Aug 18, 2026
XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1...
Moderate
Unreviewed
CVE-2026-73238
was published
Aug 12, 2026
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from...
Moderate
Unreviewed
CVE-2026-73237
was published
Aug 12, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-34497
was published
Jul 31, 2026
A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when...
Moderate
Unreviewed
CVE-2026-48910
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API