GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
511 advisories
Filter by severity
A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of...
Critical
Unreviewed
CVE-2026-76178
was published
Sep 3, 2026
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing...
Critical
Unreviewed
CVE-2026-84695
was published
Sep 2, 2026
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could...
Critical
Unreviewed
CVE-2026-73700
was published
Sep 1, 2026
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by...
Critical
Unreviewed
CVE-2026-84189
was published
Sep 1, 2026
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint,...
Critical
Unreviewed
CVE-2026-82654
was published
Aug 30, 2026
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog()...
Critical
Unreviewed
CVE-2026-82653
was published
Aug 30, 2026
An improper neutralization of input during web page generation ('Cross-site Scripting')...
Critical
Unreviewed
CVE-2026-40541
was published
Aug 28, 2026
Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. ...
Critical
Unreviewed
CVE-2026-82090
was published
Aug 28, 2026
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant...
Critical
Unreviewed
CVE-2026-8445
was published
Aug 23, 2026
SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference...
Critical
Unreviewed
CVE-2026-75916
was published
Aug 19, 2026
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's...
Critical
Unreviewed
CVE-2026-75917
was published
Aug 19, 2026
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration...
Critical
Unreviewed
CVE-2026-21580
was published
Aug 19, 2026
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss()...
Critical
Unreviewed
CVE-2026-75828
was published
Aug 18, 2026
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation...
Critical
Unreviewed
CVE-2026-74902
was published
Aug 18, 2026
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources...
Critical
Unreviewed
CVE-2026-75626
was published
Aug 18, 2026
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when...
Critical
Unreviewed
CVE-2026-74800
was published
Aug 17, 2026
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select...
Critical
Unreviewed
CVE-2026-73050
was published
Aug 16, 2026
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates...
Critical
Unreviewed
CVE-2026-73052
was published
Aug 16, 2026
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji...
Critical
Unreviewed
CVE-2026-73053
was published
Aug 16, 2026
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation,...
Critical
Unreviewed
CVE-2026-73042
was published
Aug 16, 2026
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template...
Critical
Unreviewed
CVE-2026-73043
was published
Aug 16, 2026
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing...
Critical
Unreviewed
CVE-2026-73044
was published
Aug 16, 2026
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the...
Critical
Unreviewed
CVE-2026-73041
was published
Aug 16, 2026
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low...
Critical
Unreviewed
CVE-2026-73329
was published
Aug 12, 2026
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability...
Critical
Unreviewed
CVE-2026-57858
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API