GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,865 advisories
Filter by severity
OS Command Injection in devcert-sanscache
Critical
CVE-2019-10778
was published
for
devcert-sanscache
(npm)
Apr 14, 2020
Predictable password in Keycloak
Critical
CVE-2020-1731
was published
for
org.keycloak:keycloak-core
(Maven)
Apr 15, 2020
Negative charge in shopping cart in Shopizer
Critical
CVE-2020-11007
was published
for
com.shopizer:sm-core-model
(Maven)
Apr 22, 2020
Command Injection in npm-programmatic
Critical
CVE-2020-7614
was published
for
npm-programmatic
(npm)
Apr 23, 2020
jackson-databind mishandles the interaction between serialization gadgets and typing
Critical
CVE-2020-9546
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Apr 23, 2020
Command Injection in hot-formula-parser
Critical
CVE-2020-6836
was published
for
hot-formula-parser
(npm)
May 6, 2020
Potential Code Injection in Sprout Forms
Critical
CVE-2020-11056
was published
for
barrelstrength/sprout-base-email
(Composer)
May 8, 2020
False-negative validation results in MINT transactions with invalid baton
Critical
CVE-2020-11071
was published
for
slpjs
(npm)
May 12, 2020
False-negative validation results in MINT transactions with invalid baton
Critical
CVE-2020-11072
was published
for
slp-validate
(npm)
May 12, 2020
Arbitrary file write in actionpack-page_caching gem
Critical
CVE-2020-8159
was published
for
actionpack-page_caching
(RubyGems)
May 13, 2020
curlrequest allows execution of arbitrary commands
Critical
CVE-2020-7646
was published
for
curlrequest
(npm)
May 13, 2020
jackson-databind mishandles the interaction between serialization gadgets and typing
Critical
CVE-2020-9548
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
May 15, 2020
jackson-databind mishandles the interaction between serialization gadgets and typing
Critical
CVE-2020-9547
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
May 15, 2020
Remote code execution in Apache Commons Configuration
Critical
CVE-2020-1953
was published
for
org.apache.commons:commons-configuration2
(Maven)
May 21, 2020
Apache Camel Netty enables Java deserialization by default
Critical
CVE-2020-11973
was published
for
org.apache.camel:camel-netty
(Maven)
May 21, 2020
ActiveSupport potentially unintended unmarshalling of user-provided objects in MemCacheStore and RedisCacheStore
Critical
CVE-2020-8165
was published
for
activesupport
(RubyGems)
May 26, 2020
Exposure of Sensitive Information to an Unauthorized Actor in AEgir
Critical
CVE-2020-11059
was published
for
aegir
(npm)
May 27, 2020
Arbitrary shell command execution in logkitty
Critical
CVE-2020-8149
was published
for
logkitty
(npm)
Jun 5, 2020
Django Rest Framework jwt allows obtaining new token from notionally invalidated token
Critical
CVE-2020-10594
was published
for
drf-jwt
(pip)
Jun 5, 2020
File system access via H2 in Apache Ignite
Critical
CVE-2020-1963
was published
for
org.apache.ignite:ignite-core
(Maven)
Jun 5, 2020
dom4j allows External Entities by default which might enable XXE attacks
Critical
CVE-2020-10683
was published
for
dom4j:dom4j
(Maven)
Jun 5, 2020
Insecure Deserialization in Apache XML-RPC
Critical
CVE-2019-17570
was published
for
org.apache.xmlrpc:xmlrpc
(Maven)
Jun 10, 2020
Validation Bypass in schema-inspector
Critical
CVE-2019-10781
was published
for
schema-inspector
(npm)
Jun 10, 2020
Prototype Pollution in ini-parser
Critical
CVE-2020-7617
was published
for
ini-parser
(npm)
Jun 10, 2020
ProTip!
Advisories are also available from the
GraphQL API