GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
467 advisories
Filter by severity
Cross-Site Scripting in bootstrap-vue
High
GHSA-c7pp-x73h-4m2v
was published
for
bootstrap-vue
(npm)
Sep 2, 2020
Cross-Site Scripting in semantic-ui-search
High
GHSA-p9vv-3945-x93h
was published
for
semantic-ui-search
(npm)
Sep 2, 2020
Cross-Site Scripting in mermaid
High
GHSA-w32g-5hqp-gg6q
was published
for
mermaid
(npm)
Sep 2, 2020
Cross-Site Scripting in md-data-table
High
GHSA-hgr5-82rc-p936
was published
for
md-data-table
(npm)
Sep 1, 2020
Cross-Site Scripting in react-marked-markdown
High
GHSA-m7qm-r2r5-f77q
was published
for
react-marked-markdown
(npm)
Sep 1, 2020
Cross-Site Scripting (XSS) in pivottable
High
CVE-2016-1000241
was published
for
pivottable
(npm)
Sep 1, 2020
fuelux vulnerable to Cross-Site Scripting in Pillbox feature
High
CVE-2016-1000235
was published
for
fuelux
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
High
CVE-2016-1000233
was published
for
swagger-ui
(npm)
Sep 1, 2020
XSS in client rendered block templates in rendr
High
CVE-2016-1000230
was published
for
rendr
(npm)
Sep 1, 2020
Cross-Site Scripting in bootstrap-tagsinput
High
CVE-2016-1000227
was published
for
bootstrap-tagsinput
(npm)
Sep 1, 2020
DataTable Vulnerable to Cross-Site Scripting
High
CVE-2015-6584
was published
for
datatables
(Composer)
Aug 31, 2020
Cross-Site Scripting in highcharts
High
GHSA-gr4j-r575-g665
was published
for
highcharts
(npm)
Aug 25, 2020
Cross-Site Scripting in @progress/kendo-angular-editor
High
GHSA-j7wp-vjj6-cp5m
was published
for
@progress/kendo-angular-editor
(npm)
Aug 11, 2020
Stored XSS in TimelineJS3
High
CVE-2020-15092
was published
for
@knight-lab/timelinejs
(npm)
Jul 9, 2020
Cross-site Scripting in Sanitize
High
CVE-2020-4054
was published
for
sanitize
(RubyGems)
Jun 16, 2020
The filename of uploaded files vulnerable to stored XSS
High
CVE-2020-4041
was published
for
bolt/bolt
(Composer)
Jun 9, 2020
Reflected XSS in GraphQL Playground
High
CVE-2020-4038
was published
for
graphql-playground-html
(npm)
Jun 9, 2020
ProTip!
Advisories are also available from the
GraphQL API