GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
30,712 advisories
Filter by severity
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows...
Moderate
Unreviewed
CVE-2024-56377
was published
Jan 10, 2025
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6...
Moderate
Unreviewed
CVE-2024-56376
was published
Jan 10, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13305
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13301
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13298
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13294
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13308
was published
Jan 9, 2025
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13262
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13283
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13273
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13287
was published
Jan 9, 2025
A cross-site scripting (XSS) vulnerability in Opencode Mobile Collect Call v5.4.7 allows...
Moderate
Unreviewed
CVE-2024-55494
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13292
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13286
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2024-13289
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13247
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13245
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13252
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13237
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-13238
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22813
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22827
was published
Jan 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22824
was published
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API