GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,407 advisories
Filter by severity
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin...
High
Unreviewed
CVE-2026-84673
was published
Sep 2, 2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard...
High
Unreviewed
CVE-2026-84665
was published
Sep 2, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log...
High
Unreviewed
CVE-2026-84648
was published
Sep 2, 2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
High
Unreviewed
CVE-2026-76782
was published
Sep 2, 2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
High
Unreviewed
CVE-2026-76759
was published
Sep 2, 2026
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to...
High
Unreviewed
CVE-2026-84803
was published
Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.
High
Unreviewed
CVE-2026-81771
was published
Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
High
Unreviewed
CVE-2026-81775
was published
Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by...
High
Unreviewed
CVE-2026-81289
was published
Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.
High
Unreviewed
CVE-2026-81770
was published
Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5...
High
Unreviewed
CVE-2026-81288
was published
Sep 2, 2026
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2026-75528
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-82883
was published
Sep 2, 2026
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content...
High
Unreviewed
CVE-2026-81807
was published
Sep 2, 2026
The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted...
High
Unreviewed
CVE-2026-81737
was published
Sep 2, 2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not...
High
Unreviewed
CVE-2026-19723
was published
Sep 2, 2026
The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field...
High
Unreviewed
CVE-2026-77792
was published
Sep 2, 2026
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters...
High
Unreviewed
CVE-2026-12865
was published
Sep 2, 2026
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated...
High
Unreviewed
CVE-2026-73781
was published
Sep 1, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
High
Unreviewed
CVE-2026-73703
was published
Sep 1, 2026
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
High
GHSA-f8fg-pg57-v4j8
was published
for
league/commonmark
(Composer)
Sep 1, 2026
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP...
High
Unreviewed
CVE-2026-84192
was published
Sep 1, 2026
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
High
Unreviewed
CVE-2026-19914
was published
Sep 1, 2026
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
High
Unreviewed
CVE-2026-19573
was published
Sep 1, 2026
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is...
High
Unreviewed
CVE-2026-19796
was published
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API