GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
159 advisories
Filter by severity
Improper Input Validation in network-manager
Critical
CVE-2019-10786
was published
for
network-manager
(npm)
Apr 13, 2021
netmask npm package mishandles octal input data
Moderate
CVE-2021-29418
was published
for
netmask
(npm)
Mar 29, 2021
Regular Expression Denial-of-Service in npm schema-inspector
High
CVE-2021-21267
was published
for
schema-inspector
(npm)
Mar 19, 2021
URIjs Hostname spoofing via backslashes in URL
High
CVE-2021-27516
was published
for
urijs
(npm)
Mar 1, 2021
Hostname spoofing via backslashes in URL
Moderate
CVE-2020-26291
was published
for
urijs
(npm)
Dec 30, 2020
ReDOS vulnerabities: multiple grammars
Moderate
GHSA-7wwv-vh3v-89cq
was published
for
@highlightjs/cdn-assets
(npm)
Dec 4, 2020
Prototype pollution in object-path
High
CVE-2020-15256
was published
for
object-path
(npm)
Oct 19, 2020
File restriction bypass in socket.io-file
High
GHSA-6495-8jvh-f28x
was published
for
socket.io-file
(npm)
Oct 2, 2020
Environment Variable Injection in GitHub Actions
Low
CVE-2020-15228
was published
for
@actions/core
(npm)
Oct 1, 2020
User Impersonation in converse.js
Moderate
CVE-2017-5858
was published
for
converse.js
(npm)
Sep 11, 2020
The `size` option isn't honored after following a redirect in node-fetch
Low
CVE-2020-15168
was published
for
node-fetch
(npm)
Sep 10, 2020
Remote Code Execution in pi_video_recording
High
GHSA-9wjh-jr2j-6r4x
was published
for
pi_video_recording
(npm)
Sep 2, 2020
Remote Code Execution in office-converter
High
GHSA-9p64-h5q4-phpm
was published
for
office-converter
(npm)
Sep 2, 2020
Remote Code Execution in pomelo-monitor
High
GHSA-m5ch-gx8g-rg73
was published
for
pomelo-monitor
(npm)
Sep 2, 2020
Improper Input Validation in sails-hook-sockets
High
CVE-2018-21036
was published
for
sails-hook-sockets
(npm)
Jul 24, 2020
Prototype Pollution Protection Bypass in qs
High
CVE-2017-1000048
was published
for
qs
(npm)
Apr 30, 2020
Command Injection in npm-programmatic
Critical
CVE-2020-7614
was published
for
npm-programmatic
(npm)
Apr 23, 2020
Denial of Service in uap-core when processing crafted User-Agent strings
Moderate
CVE-2020-5243
was published
for
uap-core
(RubyGems)
Feb 20, 2020
ProTip!
Advisories are also available from the
GraphQL API