Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,015 advisories

Loading
OS Command Injection in install-package Critical
CVE-2020-7629 was published for install-package (npm) Feb 10, 2022
OS Command Injection in git-add-remote Critical
CVE-2020-7630 was published for git-add-remote (npm) Feb 10, 2022
OS Command Injection in node-key-sender Critical
CVE-2020-7627 was published for node-key-sender (npm) Feb 10, 2022
Withdrawn Advisory: OS Command Injection in effect Critical
CVE-2020-7624 was published for effect (npm) Feb 10, 2022 withdrawn
Fidget-Grep
Injection in op-browser Critical
CVE-2020-7625 was published for op-browser (npm) Feb 10, 2022
karma-mojo enables OS Command Injection Critical
CVE-2020-7626 was published for karma-mojo (npm) Feb 10, 2022
Code injection in @rkesters/gnuplot Critical
CVE-2021-29369 was published for @rkesters/gnuplot (npm) Feb 10, 2022
OS Command Injection in jscover Critical
CVE-2020-7623 was published for jscover (npm) Feb 10, 2022
OS Command Injection in strong-nginx-controller Critical
CVE-2020-7621 was published for strong-nginx-controller (npm) Feb 10, 2022
push-dir Enables OS Command Injection Critical
CVE-2019-10803 was published for push-dir (npm) Feb 9, 2022
Prototype Pollution in js-data Critical
CVE-2020-28442 was published for js-data (npm) Feb 9, 2022
Prototype Pollution leading to Remote Code Execution in superjson Critical
CVE-2022-23631 was published for blitz (npm) Feb 9, 2022
paul-gerste-sonarsource
Joplin Vulnerable to Code Injection Critical
CVE-2022-23340 was published for joplin (npm) Feb 9, 2022
Path Traversal in w-zip Critical
CVE-2022-0401 was published for w-zip (npm) Feb 2, 2022
Exposure of Resource to Wrong Sphere in Zip-Local Critical
CVE-2021-23484 was published for zip-local (npm) Feb 1, 2022
Access of Resource Using Incompatible Type in Hermes Critical
CVE-2021-24044 was published for hermes-engine (npm) Jan 16, 2022
Prototype Pollution in realms-shim Critical
CVE-2021-23543 was published for realms-shim (npm) Jan 13, 2022
Prototype Pollution in realms-shim Critical
CVE-2021-23594 was published for realms-shim (npm) Jan 12, 2022
Zalgo-like output that crashes the server Critical
GHSA-2w8g-m5j8-7m87 was published for @soketi/soketi (npm) Jan 12, 2022
OS Command Injection in diskusage-ng Critical
CVE-2020-7631 was published for diskusage-ng (npm) Jan 7, 2022
OS Command Injection in node-mpv Critical
CVE-2020-7632 was published for node-mpv (npm) Jan 7, 2022
Prototype Pollution in js-data Critical
CVE-2021-23574 was published for js-data (npm) Jan 6, 2022
Command Injection in node-windows Critical
CVE-2021-45459 was published for node-windows (npm) Jan 5, 2022
dwisiswant0 tdunlap607
Remote Code Execution in npm-groovy-lint Critical
GHSA-qc22-qwm9-j8rx was published for npm-groovy-lint (npm) Dec 20, 2021
Code Injection in md-to-pdf. Critical
CVE-2021-23639 was published for md-to-pdf (npm) Dec 16, 2021
ProTip! Advisories are also available from the GraphQL API