GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,492
Maven
5,000+
npm
4,114
NuGet
735
pip
3,936
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
36,953 advisories
Filter by severity
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and...
Moderate
Unreviewed
CVE-2025-43785
was published
Sep 10, 2025
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user...
Moderate
Unreviewed
CVE-2025-8681
was published
Sep 10, 2025
A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an...
Moderate
Unreviewed
CVE-2025-20328
was published
Sep 10, 2025
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM ...
Moderate
Unreviewed
CVE-2025-20330
was published
Sep 10, 2025
Webrecorder packages are vulnerable to XSS through 404 error handling logic
High
CVE-2025-58765
was published
for
@webrecorder/archivewebpage
(npm)
Sep 10, 2025
A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9715
was published
Sep 10, 2025
A flaw has been found in O2OA up to 10.0-410. Affected is an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-9681
was published
Sep 10, 2025
A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file...
Moderate
Unreviewed
CVE-2025-9680
was published
Sep 10, 2025
Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-40725
was published
Sep 10, 2025
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-9367
was published
Sep 10, 2025
The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-10126
was published
Sep 10, 2025
The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-9857
was published
Sep 10, 2025
The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-8388
was published
Sep 10, 2025
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to...
Moderate
Unreviewed
CVE-2025-49461
was published
Sep 10, 2025
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-7746
was published
Sep 9, 2025
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Moderate
Unreviewed
CVE-2025-55054
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34177
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34178
was published
Sep 9, 2025
Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
Moderate
Unreviewed
CVE-2025-44595
was published
Sep 9, 2025
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as ...
Moderate
Unreviewed
CVE-2025-44593
was published
Sep 9, 2025
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross...
Moderate
Unreviewed
CVE-2025-36125
was published
Sep 9, 2025
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP...
Moderate
Unreviewed
CVE-2025-43786
was published
Sep 9, 2025
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is...
Moderate
Unreviewed
CVE-2025-34174
was published
Sep 9, 2025
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter...
Moderate
Unreviewed
CVE-2025-34175
was published
Sep 9, 2025
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent...
Moderate
Unreviewed
CVE-2025-34172
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API