GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
37,844 advisories
Filter by severity
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
Moderate
Unreviewed
CVE-2026-73731
was published
Sep 1, 2026
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
Moderate
CVE-2026-84371
was published
for
sanitize-html
(npm)
Sep 1, 2026
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
Moderate
CVE-2026-58191
was published
for
@appium/base-driver
(npm)
Sep 1, 2026
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type...
Moderate
Unreviewed
CVE-2026-84232
was published
Sep 1, 2026
The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-7877
was published
Sep 1, 2026
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS...
Moderate
Unreviewed
CVE-2026-19471
was published
Sep 1, 2026
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP...
Moderate
Unreviewed
CVE-2026-84193
was published
Sep 1, 2026
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the...
Moderate
Unreviewed
CVE-2026-84188
was published
Sep 1, 2026
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages...
Moderate
Unreviewed
CVE-2026-84191
was published
Sep 1, 2026
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-15101
was published
Sep 1, 2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2026-16788
was published
Sep 1, 2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2026-16786
was published
Sep 1, 2026
The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for...
Moderate
Unreviewed
CVE-2026-75980
was published
Sep 1, 2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor...
Moderate
Unreviewed
CVE-2026-75964
was published
Sep 1, 2026
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
Moderate
Unreviewed
CVE-2026-18488
was published
Sep 1, 2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2026-13203
was published
Sep 1, 2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-12747
was published
Sep 1, 2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2026-16787
was published
Sep 1, 2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor...
Moderate
Unreviewed
CVE-2026-75965
was published
Sep 1, 2026
Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.
Moderate
Unreviewed
CVE-2026-81778
was published
Aug 31, 2026
TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application...
Moderate
Unreviewed
CVE-2025-63607
was published
Aug 31, 2026
Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208...
Moderate
Unreviewed
CVE-2026-51153
was published
Aug 31, 2026
Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket...
Moderate
Unreviewed
CVE-2026-76985
was published
Aug 31, 2026
Improper neutralization of input during web page generation in Apache Wicket.
org.apache.wicket...
Moderate
Unreviewed
CVE-2026-76986
was published
Aug 31, 2026
AjaxEditableChoiceLabel in wicket-extensions, when constructed with a non-null IChoiceRenderer,...
Moderate
Unreviewed
CVE-2026-75802
was published
Aug 31, 2026
ProTip!
Advisories are also available from the
GraphQL API