GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,296 advisories
Filter by severity
grapesjs before 0.19.5 vulnerable to Cross-site Scripting
Moderate
CVE-2022-21802
was published
for
grapesjs
(npm)
Jul 26, 2022
Prototype Pollution in open-graph
Moderate
CVE-2021-23419
was published
for
open-graph
(npm)
Sep 1, 2021
Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util
Moderate
CVE-2019-10806
was published
for
vega-util
(npm)
May 7, 2021
@netlify/ipx vulnerable to Full Response SSRF and Stored XSS via Cache Poisoning and Improper Host Validation
Moderate
CVE-2022-39239
was published
for
@netlify/ipx
(npm)
Sep 21, 2022
Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware
Moderate
CVE-2020-7616
was published
for
express-mock-middleware
(npm)
Dec 9, 2021
Improperly Controlled Modification of Dynamically-Determined Object Attributes in querymen
Moderate
CVE-2020-7600
was published
for
querymen
(npm)
May 7, 2021
confinit vulnerable to prototype pollution
Moderate
CVE-2020-7638
was published
for
confinit
(npm)
Apr 7, 2020
Prototype pollution in multi-ini
Moderate
CVE-2020-28460
was published
for
multi-ini
(npm)
Apr 13, 2021
Prototype pollution in class-transformer
Moderate
CVE-2020-7637
was published
for
class-transformer
(npm)
Apr 7, 2020
Solana Pay Vulnerable to Weakness in Transfer Validation Logic
Moderate
CVE-2022-35917
was published
for
@solana/pay
(npm)
Aug 6, 2022
Cross-Site Scripting in min-http-server
Moderate
CVE-2019-5457
was published
for
min-http-server
(npm)
Jul 31, 2019
Path Traversal in serve-here.js
Moderate
CVE-2019-5444
was published
for
serve-here.js
(npm)
Sep 22, 2021
Cross site scripting in mobiledoc-kit
Moderate
CVE-2022-2932
was published
for
mobiledoc-kit
(npm)
Aug 23, 2022
Directus vulnerable to unhandled exception on illegal filename_disk value
Moderate
CVE-2022-36031
was published
for
directus
(npm)
Aug 30, 2022
Lack of protection against cookie tossing attacks in fastify-csrf
Moderate
CVE-2021-29624
was published
for
fastify-csrf
(npm)
May 17, 2021
parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing
Moderate
CVE-2022-3224
was published
for
parse-url
(npm)
Sep 16, 2022
Matrix-appservice-irc vulnerable to sql injection via roomIds argument
Moderate
CVE-2022-3971
was published
for
matrix-appservice-irc
(npm)
Nov 13, 2022
deep-object-diff vulnerable to Prototype Pollution
Moderate
CVE-2022-41713
was published
for
deep-object-diff
(npm)
Nov 4, 2022
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
Moderate
CVE-2022-39384
was published
for
@openzeppelin/contracts
(npm)
Dec 14, 2021
Cross-site scripting vulnerability in TinyMCE alerts
Moderate
CVE-2022-23494
was published
for
TinyMCE
(Composer)
Dec 8, 2022
Jodit Editor vulnerable to Cross-site Scripting
Moderate
CVE-2022-23461
was published
for
jodit
(npm)
Sep 25, 2022
matrix-appservice-irc vulnerable to IRC mode parameter confusion
Moderate
CVE-2022-39202
was published
for
matrix-appservice-irc
(npm)
Sep 15, 2022
easywebpack-cli Path Traversal vulnerability
Moderate
CVE-2020-24855
was published
for
@easy-team/easywebpack-cli
(npm)
Dec 15, 2022
Cross-site scripting in @shopify/koa-shopify-auth
Moderate
CVE-2020-8176
was published
for
@shopify/koa-shopify-auth
(npm)
May 17, 2021
ProTip!
Advisories are also available from the
GraphQL API