GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,127 advisories
Filter by severity
Pandao editor.md vulnerable to DOM XSS
Moderate
CVE-2018-19056
was published
for
editor.md
(npm)
Nov 9, 2018
Remote Memory Exposure in request
Moderate
CVE-2017-16026
was published
for
request
(npm)
Nov 9, 2018
Tmp files readable by other users in sync-exec
Moderate
CVE-2017-16024
was published
for
sync-exec
(npm)
Nov 9, 2018
Cross-Site Scripting (XSS) in restify
Moderate
CVE-2017-16018
was published
for
restify
(npm)
Nov 9, 2018
Cross-Site Scripting in sanitize-html
Moderate
CVE-2017-16017
was published
for
sanitize-html
(npm)
Nov 9, 2018
Cross-Site Scripting in morris.js
Moderate
CVE-2017-16022
was published
for
morris.js
(npm)
Nov 9, 2018
Cross-Site Scripting in sanitize-html
Moderate
CVE-2017-16016
was published
for
sanitize-html
(npm)
Nov 9, 2018
Content Injection via TileJSON attribute in mapbox.js
Moderate
CVE-2017-1000042
was published
for
mapbox-rails
(RubyGems)
Nov 9, 2018
Insufficient Error Handling in http-proxy
High
CVE-2017-16014
was published
for
http-proxy
(npm)
Nov 9, 2018
Content Injection via TileJSON Name in mapbox.js
Moderate
CVE-2017-1000043
was published
for
mapbox-rails
(RubyGems)
Nov 9, 2018
windows-build-tools downloads Resources over HTTP
High
CVE-2017-16003
was published
for
windows-build-tools
(npm)
Nov 9, 2018
Cross-Site Scripting in html-janitor
Moderate
CVE-2017-0931
was published
for
html-janitor
(npm)
Nov 9, 2018
Header Forgery in http-signature
High
CVE-2017-16005
was published
for
http-signature
(npm)
Nov 9, 2018
Ckeditor XSS Vulnerability
Moderate
CVE-2018-17960
was published
for
ckeditor
(Composer)
Nov 21, 2018
Cross-site Scripting in yapi-vendor
Moderate
CVE-2018-17574
was published
for
yapi-vendor
(npm)
Nov 21, 2018
ProTip!
Advisories are also available from the
GraphQL API