GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
21 advisories
Filter by severity
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
Moderate
CVE-2026-63466
was published
for
unleash-server
(npm)
Aug 21, 2026
Shescape: Home-directory disclosure in assignment context on Unix with Dash
Moderate
CVE-2026-73411
was published
for
shescape
(npm)
Jul 24, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
mathlive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2026-54705
was published
for
mathlive
(npm)
Jul 29, 2026
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Moderate
CVE-2026-64647
was published
for
next
(npm)
Jul 22, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
Moderate
CVE-2026-54287
was published
for
hono
(npm)
Jun 16, 2026
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Moderate
CVE-2026-44311
was published
for
fabric
(npm)
Jun 12, 2026
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
Moderate
CVE-2026-46496
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS
Moderate
CVE-2026-26028
was published
for
cryptpad
(npm)
May 26, 2026
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
Moderate
CVE-2026-44458
was published
for
hono
(npm)
May 9, 2026
OpenClaw has ACP CLI approval prompt ANSI escape sequence injection
Moderate
CVE-2026-35651
was published
for
openclaw
(npm)
Mar 29, 2026
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read
Moderate
GHSA-wr4h-v87w-p3r7
was published
for
h3
(npm)
Mar 18, 2026
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
KaTeX \htmlData does not validate attribute names
Moderate
CVE-2025-23207
was published
for
katex
(npm)
Jan 17, 2025
MathLive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2025-29049
was published
for
mathlive
(npm)
Jan 21, 2025
React Developer Tools extension Improper Authorization vulnerability
Moderate
CVE-2023-5654
was published
for
react-devtools-core
(npm)
Oct 19, 2023
KaTeX's `\includegraphics` does not escape filename
Moderate
CVE-2024-28245
was published
for
katex
(npm)
Mar 25, 2024
Misinterpretation of malicious XML input
Moderate
CVE-2021-32796
was published
for
@xmldom/xmldom
(npm)
Aug 3, 2021
Critters Cross-site Scripting Vulnerability
Moderate
CVE-2023-3481
was published
for
critters
(npm)
Aug 11, 2023
OpenZeppelin Contracts vulnerable to Improper Escaping of Output
Moderate
CVE-2023-40014
was published
for
@openzeppelin/contracts
(npm)
Aug 11, 2023
ProTip!
Advisories are also available from the
GraphQL API