GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,127 advisories
Filter by severity
Incorrect handling of CORS preflight request headers in hapi
Moderate
CVE-2015-9236
was published
for
hapi
(npm)
Jun 7, 2018
Cross-Site Scripting in @risingstack/protect
Moderate
CVE-2018-1000160
was published
for
@risingstack/protect
(npm)
Apr 25, 2018
Downloads Resources over HTTP in openframe-glslviewer
High
CVE-2016-10607
was published
for
openframe-glslviewer
(npm)
Feb 18, 2019
Downloads Resources over HTTP in go-ipfs-dep
High
CVE-2016-10563
was published
for
go-ipfs-dep
(npm)
Feb 18, 2019
Downloads Resources over HTTP in pk-app-wonderbox
High
CVE-2016-10685
was published
for
pk-app-wonderbox
(npm)
Feb 18, 2019
Path Traversal in superstatic
High
GHSA-wm77-q74p-5763
was published
for
superstatic
(npm)
Jul 27, 2018
Downloads Resources over HTTP in nodewebkit
High
CVE-2016-10580
was published
for
nodewebkit
(npm)
Feb 18, 2019
Downloads Resources over HTTP in arcanist
Moderate
CVE-2016-10683
was published
for
arcanist
(npm)
Feb 18, 2019
Downloads Resources over HTTP in openframe-image
High
CVE-2016-10616
was published
for
openframe-image
(npm)
Feb 18, 2019
Downloads Resources over HTTP in product-monitor
High
CVE-2016-10567
was published
for
product-monitor
(npm)
Feb 18, 2019
Moderate severity vulnerability that affects moment
Moderate
GHSA-hxf5-mg84-pj4m
was published
for
moment
(npm)
Jul 31, 2018
•
withdrawn
Moderate severity vulnerability that affects ember
Moderate
GHSA-vxp4-25qp-86qh
was published
for
ember
(npm)
Oct 24, 2017
•
withdrawn
Downloads Resources over HTTP in redis-srvr
High
CVE-2016-10639
was published
for
redis-srvr
(npm)
Feb 18, 2019
Moderate severity vulnerability that affects send
Moderate
GHSA-pgv6-jrvv-75jp
was published
for
send
(npm)
Oct 9, 2018
•
withdrawn
Sensitive information exposure through logs in npm-registry-fetch
Moderate
GHSA-jmqm-f2gx-4fjv
was published
for
npm-registry-fetch
(npm)
Jul 7, 2020
Multiple XSS Filter Bypasses in validator
Moderate
CVE-2013-7454
was published
for
validator
(npm)
Oct 24, 2017
ReDoS via long UserAgent header in ua-parser
High
CVE-2017-16086
was published
for
ua-parser
(npm)
Jul 24, 2018
Command Injection in macaddress
Critical
CVE-2018-13797
was published
for
macaddress
(npm)
Sep 6, 2018
Downloads Resources over HTTP in unicode
High
CVE-2016-10578
was published
for
unicode
(npm)
Feb 18, 2019
Cross-Site Scripting in simple-markdown
Moderate
CVE-2019-9844
was published
for
simple-markdown
(npm)
Apr 9, 2019
Downloads Resources over HTTP in jvminstall
High
CVE-2016-10631
was published
for
jvminstall
(npm)
Feb 18, 2019
Downloads Resources over HTTP in imageoptim
High
CVE-2016-10596
was published
for
imageoptim
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API