GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,587 advisories
Filter by severity
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.7.4 does not sanitise and...
Low
Unreviewed
CVE-2024-13314
was published
Feb 21, 2025
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-12683
was published
Mar 26, 2025
The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings,...
Low
Unreviewed
CVE-2025-1452
was published
Mar 25, 2025
Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper...
Low
Unreviewed
CVE-2025-23379
was published
May 6, 2025
The Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social...
Low
Unreviewed
CVE-2024-13615
was published
Mar 11, 2025
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not...
Low
Unreviewed
CVE-2025-0627
was published
Apr 28, 2025
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1524
was published
Apr 17, 2025
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1525
was published
Apr 17, 2025
The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings...
Low
Unreviewed
CVE-2024-9771
was published
Apr 28, 2025
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of...
Low
Unreviewed
CVE-2024-12273
was published
Apr 29, 2025
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1523
was published
Apr 17, 2025
The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not...
Low
Unreviewed
CVE-2024-11924
was published
Apr 17, 2025
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
Low
CVE-2025-46350
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Stored XSS Vulnerability in Comments
Low
CVE-2025-46346
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes
Low
CVE-2025-31697
was published
for
drupal/formatter_suite
(Composer)
Apr 1, 2025
Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31696
was published
for
drupal/rapidoc_elements_field_formatter
(Composer)
Apr 1, 2025
Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31695
was published
for
drupal/link_field_display_mode_formatter
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-12769
was published
Mar 25, 2025
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a...
Low
Unreviewed
CVE-2024-52887
was published
Apr 27, 2025
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Low
Unreviewed
CVE-2025-46618
was published
Apr 25, 2025
Insufficient sanitization in HCL Leap allows
client-side script injection in the authoring...
Low
Unreviewed
CVE-2024-30114
was published
Apr 24, 2025
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low
CVE-2024-45965
was published
for
contao/contao
(Composer)
Oct 2, 2024
•
withdrawn
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a...
Low
Unreviewed
CVE-2024-42195
was published
Dec 5, 2024
ProTip!
Advisories are also available from the
GraphQL API