GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,583 advisories
Filter by severity
Ruby-ffi has a DLL loading issue
High
CVE-2018-1000201
was published
for
ffi
(RubyGems)
Aug 31, 2018
simplehttpserver allows directory traversal and file listing
High
CVE-2018-3787
was published
for
simplehttpserver
(npm)
Sep 6, 2018
aiohttp-session Session Fixation vulnerability
High
CVE-2018-1000519
was published
for
aiohttp-session
(pip)
Sep 13, 2018
Topydo Improper Input Validation vulnerability
High
CVE-2018-1000523
was published
for
topydo
(pip)
Sep 13, 2018
websockets is vulnerable to denial of service by memory exhaustion
High
CVE-2018-1000518
was published
for
websockets
(pip)
Sep 17, 2018
Denial of service or RCE from libxml2 and libxslt
High
CVE-2015-8806
was published
for
nokogiri
(RubyGems)
Sep 17, 2018
apk-parser2 downloads Resources over HTTP
High
CVE-2016-10632
was published
for
apk-parser2
(npm)
Sep 18, 2018
Downloads Resources over HTTP in node-bsdiff-android
High
CVE-2016-10641
was published
for
node-bsdiff-android
(npm)
Sep 18, 2018
Jekyll allows attackers to access arbitrary files by specifying a symlink
High
CVE-2018-17567
was published
for
jekyll
(RubyGems)
Sep 28, 2018
Django vulnerable to information leakage in AuthenticationForm
High
CVE-2018-6188
was published
for
Django
(pip)
Oct 3, 2018
Spark allows remote attackers to read arbitrary files via a .. (dot dot) in the URI
High
CVE-2016-9177
was published
for
com.sparkjava:spark-core
(Maven)
Oct 4, 2018
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
High
CVE-2016-9878
was published
for
org.springframework:spring-webmvc
(Maven)
Oct 4, 2018
Regular Expression Denial of Service in negotiator
High
CVE-2016-10539
was published
for
negotiator
(npm)
Oct 9, 2018
Denial-of-Service Extended Event Loop Blocking in qs
High
CVE-2014-10064
was published
for
qs
(npm)
Oct 9, 2018
High severity vulnerability that affects uglify-js
High
GHSA-g6f4-j6c2-w3p3
was published
for
uglify-js
(npm)
Oct 9, 2018
•
withdrawn
Regular Expression Denial of Service in minimatch
High
CVE-2016-10540
was published
for
minimatch
(npm)
Oct 9, 2018
ProTip!
Advisories are also available from the
GraphQL API