GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
37,844 advisories
Filter by severity
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
Moderate
CVE-2026-68921
was published
for
@dicebear/core
(npm)
Sep 2, 2026
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-75134
was published
Sep 2, 2026
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names,...
Moderate
Unreviewed
CVE-2026-84677
was published
Sep 2, 2026
The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content...
Moderate
Unreviewed
CVE-2026-82884
was published
Sep 2, 2026
The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets'...
Moderate
Unreviewed
CVE-2026-83547
was published
Sep 2, 2026
The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its...
Moderate
Unreviewed
CVE-2024-3773
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Moderate
Unreviewed
CVE-2026-81201
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Moderate
Unreviewed
CVE-2026-81167
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Moderate
Unreviewed
CVE-2026-81160
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Moderate
Unreviewed
CVE-2026-18986
was published
Sep 2, 2026
Sulu: Stored XSS via media download inline-disposition override
Moderate
CVE-2026-82396
was published
for
sulu/sulu
(Composer)
Sep 2, 2026
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes
Moderate
GHSA-cp6q-959q-f8rh
was published
for
@tiptap/core
(npm)
Sep 2, 2026
Livewire DOM-based cross-site scripting during client-side state handling
Moderate
CVE-2026-81887
was published
for
livewire/livewire
(Composer)
Sep 2, 2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
Moderate
Unreviewed
CVE-2026-84781
was published
Sep 2, 2026
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-84793
was published
Sep 2, 2026
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.
Moderate
Unreviewed
CVE-2026-83562
was published
Sep 2, 2026
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url`...
Moderate
Unreviewed
CVE-2026-3850
was published
Sep 2, 2026
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-7963
was published
Sep 2, 2026
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not...
Moderate
Unreviewed
CVE-2026-19719
was published
Sep 2, 2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not...
Moderate
Unreviewed
CVE-2025-15664
was published
Sep 2, 2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not...
Moderate
Unreviewed
CVE-2025-15663
was published
Sep 2, 2026
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content...
Moderate
Unreviewed
CVE-2026-3851
was published
Sep 2, 2026
NocoBase fails to sanitize rich text field values in the read renderer, allowing users with...
Moderate
Unreviewed
CVE-2026-84701
was published
Sep 2, 2026
AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization,...
Moderate
Unreviewed
CVE-2026-84477
was published
Sep 2, 2026
Cypht before 2.12.2 contains a cross-site scripting vulnerability in the contacts module that...
Moderate
Unreviewed
CVE-2026-73524
was published
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API