Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,296 advisories

Loading
Arbitrary code execution in kill-by-port Moderate
CVE-2021-23363 was published for kill-by-port (npm) Apr 13, 2021
Cross-site Scripting in CKEditor4 Moderate
CVE-2022-24728 was published for ckeditor4 (npm) Mar 16, 2022
Code injection in npm git Moderate
CVE-2021-23632 was published for git (npm) Mar 18, 2022
Arbitrary command execution in roar-pidusage Moderate
CVE-2021-23380 was published for roar-pidusage (npm) May 6, 2021
Utils.readChallengeTx does not verify the server account signature Moderate
CVE-2021-32738 was published for stellar-sdk (npm) Jul 2, 2021
leighmcculloch
Sandbox escape in notevil and argencoders-notevil Moderate
CVE-2021-23771 was published for argencoders-notevil (npm) Mar 18, 2022
Prototype Pollution in bodymen Moderate
CVE-2022-25296 was published for bodymen (npm) Mar 18, 2022
Improper Verification of Cryptographic Signature in `node-forge` Moderate
CVE-2022-24773 was published for node-forge (npm) Mar 18, 2022
Cross-site Scripting in @rocket.chat/livechat Moderate
CVE-2022-21830 was published for @rocket.chat/livechat (npm) Apr 3, 2022
URL Confusion When Scheme Not Supplied in medialize/uri.js Moderate
CVE-2022-1233 was published for urijs (npm) Apr 5, 2022
Cross-site Scripting in vditor Moderate
CVE-2022-0350 was published for vditor (npm) Apr 1, 2022
Cross site scripting in valine Moderate
CVE-2020-28847 was published for valine (npm) Apr 6, 2022
Cross-site Scripting in tableexport.jquery.plugin Moderate
CVE-2022-1291 was published for tableexport.jquery.plugin (npm) Apr 11, 2022
Cross-site Scripting in fullpage.js Moderate
CVE-2022-1330 was published for fullpage.js (npm) Apr 13, 2022
Incorrect Authorization in cross-fetch Moderate
CVE-2022-1365 was published for cross-fetch (npm) Apr 17, 2022
cysp
Potential Cross-site Scripting vulnerability in Hydrogen Moderate
CVE-2022-29230 was published for @shopify/hydrogen (npm) May 19, 2022
Cross-site Scripting in Auth0 Lock Moderate
CVE-2022-29172 was published for auth0-lock (npm) May 24, 2022
NextAuth.js default redirect callback vulnerable to open redirects Moderate
CVE-2022-24858 was published for next-auth (npm) Apr 22, 2022
rustyguts
Prototype Pollution in json-pointer Moderate
CVE-2021-23820 was published for json-pointer (npm) Nov 8, 2021
G-Rath
URL Redirection to Untrusted Site ('Open Redirect') in next-auth Moderate
CVE-2022-29214 was published for next-auth (npm) May 24, 2022
Ry0taK
undici before v5.8.0 vulnerable to CRLF injection in request headers Moderate
CVE-2022-31150 was published for undici (npm) Jul 21, 2022
Haxatron
Exposure of Sensitive Information to an Unauthorized Actor in nanoid Moderate
CVE-2021-23566 was published for nanoid (npm) Jan 21, 2022
baptistecs
x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting Moderate
CVE-2022-25646 was published for x-data-spreadsheet (npm) Aug 31, 2022
Improper Neutralization of Input During Web Page Generation in CKEditor4 Moderate
CVE-2020-27193 was published for ckeditor4 (npm) May 24, 2022
spellman
ProTip! Advisories are also available from the GraphQL API