GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
121,145 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22549
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22551
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22550
was published
Jan 7, 2025
Missing Authorization vulnerability in Saoshyant.1994 Saoshyant Page Builder allows Exploiting...
Moderate
Unreviewed
CVE-2025-22560
was published
Jan 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Faaiq Pretty Url allows Cross Site Request...
Moderate
Unreviewed
CVE-2025-22563
was published
Jan 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Jason Funk Title Experiments Free allows Cross...
Moderate
Unreviewed
CVE-2025-22562
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22577
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22558
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22573
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22579
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22572
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22554
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22578
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22574
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22580
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22581
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22584
was published
Jan 7, 2025
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar.
*Note:...
Moderate
Unreviewed
CVE-2025-0244
was published
Jan 7, 2025
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5...
Moderate
Unreviewed
CVE-2025-0242
was published
Jan 7, 2025
A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical...
Moderate
Unreviewed
CVE-2025-0297
was published
Jan 7, 2025
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird...
Moderate
Unreviewed
CVE-2025-0243
was published
Jan 7, 2025
When using an invalid protocol scheme, an attacker could spoof the address bar.
*Note: This...
Moderate
Unreviewed
CVE-2025-0246
was published
Jan 7, 2025
A vulnerability was found in code-projects Online Book Shop 1.0. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-0298
was published
Jan 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22511
was published
Jan 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Digital Zoom Studio Admin debug wordpress –...
Moderate
Unreviewed
CVE-2025-22503
was published
Jan 7, 2025
ProTip!
Advisories are also available from the
GraphQL API