GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
117
GitHub Actions
55
Go
4,836
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,577
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
539 advisories
Filter by severity
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site...
Critical
Unreviewed
CVE-2026-18872
was published
Sep 23, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-75689
was published
Sep 22, 2026
Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker...
Critical
Unreviewed
CVE-2026-75698
was published
Sep 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-75697
was published
Sep 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-75684
was published
Sep 22, 2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
Critical
Unreviewed
CVE-2026-82832
was published
Sep 18, 2026
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute...
Critical
Unreviewed
CVE-2026-84031
was published
Sep 18, 2026
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML...
Critical
Unreviewed
CVE-2026-93659
was published
Sep 18, 2026
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Critical
CVE-2026-75828
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's...
Critical
Unreviewed
CVE-2026-15639
was published
Sep 16, 2026
parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in...
Critical
Unreviewed
CVE-2026-90943
was published
Sep 14, 2026
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting...
Critical
Unreviewed
CVE-2026-90561
was published
Sep 13, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89255
was published
Sep 11, 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89253
was published
Sep 11, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89254
was published
Sep 11, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89256
was published
Sep 11, 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89243
was published
Sep 11, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-89249
was published
Sep 11, 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-88866
was published
Sep 10, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-88868
was published
Sep 10, 2026
WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1,...
Critical
Unreviewed
CVE-2026-88867
was published
Sep 10, 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...
Critical
Unreviewed
CVE-2026-88869
was published
Sep 10, 2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-76200
was published
Sep 8, 2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be...
Critical
Unreviewed
CVE-2026-76201
was published
Sep 8, 2026
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip
Critical
CVE-2026-85061
was published
for
maplibre-gl
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API