GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,833
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
45,404 advisories
Filter by severity
LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file...
High
Unreviewed
CVE-2026-91775
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site...
Critical
Unreviewed
CVE-2026-18872
was published
Sep 23, 2026
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
Moderate
CVE-2026-63002
was published
for
redaxo/source
(Composer)
Sep 23, 2026
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
Moderate
CVE-2026-63001
was published
for
redaxo/source
(Composer)
Sep 23, 2026
Tauri's Content Security Policy hardening, which injects a random nonce to restrict script...
High
Unreviewed
CVE-2026-95626
was published
Sep 23, 2026
Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’...
Moderate
Unreviewed
CVE-2026-5696
was published
Sep 23, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-91852
was published
Sep 23, 2026
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79]...
Moderate
Unreviewed
CVE-2026-73192
was published
Sep 23, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-91999
was published
Sep 23, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-91928
was published
Sep 23, 2026
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-5924
was published
Sep 23, 2026
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key...
Moderate
Unreviewed
CVE-2026-88997
was published
Sep 23, 2026
The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form...
Moderate
Unreviewed
CVE-2026-91073
was published
Sep 23, 2026
The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on...
Moderate
Unreviewed
CVE-2026-85006
was published
Sep 23, 2026
A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722...
Low
Unreviewed
CVE-2026-96258
was published
Sep 23, 2026
The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook...
Moderate
Unreviewed
CVE-2025-15696
was published
Sep 23, 2026
A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0....
Low
Unreviewed
CVE-2026-95957
was published
Sep 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to...
High
Unreviewed
CVE-2026-18131
was published
Sep 23, 2026
Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page...
Moderate
Unreviewed
CVE-2026-88020
was published
Sep 22, 2026
A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2026-77912
was published
Sep 22, 2026
ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the...
Moderate
Unreviewed
CVE-2026-95812
was published
Sep 22, 2026
MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content...
High
Unreviewed
CVE-2026-88415
was published
Sep 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-75689
was published
Sep 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-75684
was published
Sep 22, 2026
Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker...
Critical
Unreviewed
CVE-2026-75698
was published
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API