GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
391 advisories
Filter by severity
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
Moderate
CVE-2026-33628
was published
for
invoiceninja/invoiceninja
(Composer)
Mar 24, 2026
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
Moderate
GHSA-wr4h-v87w-p3r7
was published
for
h3
(npm)
Mar 18, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string
High
CVE-2026-32811
was published
for
github.com/dadrus/heimdall
(Go)
Mar 18, 2026
jsPDF has a PDF Object Injection via FreeText color
High
CVE-2026-31898
was published
for
jspdf
(npm)
Mar 17, 2026
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS
Moderate
CVE-2026-28499
was published
for
github.com/vapor/leaf-kit
(Swift)
Mar 16, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18...
Low
Unreviewed
CVE-2025-12697
was published
Mar 11, 2026
CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization
Moderate
CVE-2026-31859
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
OpenClaw: fetch-guard forwards custom authorization headers across cross-origin redirects
High
CVE-2026-32913
was published
for
openclaw
(npm)
Mar 9, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
High
CVE-2025-66024
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Mar 4, 2026
OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling
High
CVE-2026-31994
was published
for
openclaw
(npm)
Mar 3, 2026
lxml-html-clean has <base> tag injection through default Cleaner configuration
Moderate
CVE-2026-28350
was published
for
lxml-html-clean
(pip)
Mar 2, 2026
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
Moderate
CVE-2026-28348
was published
for
lxml-html-clean
(pip)
Mar 2, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module
Moderate
CVE-2026-27116
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-xpg8-7m6m-jf56
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Isso affected by Stored XSS via comment website field
Moderate
CVE-2026-27469
was published
for
isso
(pip)
Feb 24, 2026
jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
High
CVE-2026-25940
was published
for
jspdf
(npm)
Feb 19, 2026
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method
High
CVE-2026-25755
was published
for
jspdf
(npm)
Feb 19, 2026
Fabric.js Affected by Stored XSS via SVG Export
High
CVE-2026-27013
was published
for
fabric
(npm)
Feb 18, 2026
LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()
Moderate
CVE-2026-27016
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
Moderate
Unreviewed
CVE-2025-15312
was published
Feb 5, 2026
HtmlSanitizer has a bypass via template tag
Moderate
CVE-2026-25543
was published
for
HtmlSanitizer
(NuGet)
Feb 3, 2026
jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution
High
CVE-2026-24737
was published
for
jspdf
(npm)
Feb 2, 2026
CSS-based exfiltration of the content from partially encrypted emails when allowing remote...
Moderate
Unreviewed
CVE-2026-0818
was published
Jan 28, 2026
ProTip!
Advisories are also available from the
GraphQL API