GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,127 advisories
Filter by severity
Authentication Bypass in hapi-auth-jwt2
Critical
CVE-2016-10525
was published
for
hapi-auth-jwt2
(npm)
Feb 18, 2019
Downloads Resources over HTTP in wasdk
High
CVE-2016-10587
was published
for
wasdk
(npm)
Feb 18, 2019
Potential Command Injection in codem-transcode
High
CVE-2013-7377
was published
for
codem-transcode
(npm)
Nov 28, 2017
Downloads Resources over HTTP in native-opencv
High
CVE-2016-10658
was published
for
native-opencv
(npm)
Feb 18, 2019
Downloads Resources over HTTP in jstestdriver
High
CVE-2016-10643
was published
for
jstestdriver
(npm)
Aug 15, 2018
Regular Expression Denial of Service in parsejson
High
CVE-2017-16113
was published
for
parsejson
(npm)
Jul 24, 2018
Downloads Resources over HTTP in windows-iedriver
High
CVE-2016-10689
was published
for
windows-iedriver
(npm)
Feb 18, 2019
Cross-Site Request Forgery (CSRF) in keystone
High
CVE-2017-16570
was published
for
keystone
(npm)
Nov 30, 2017
Downloads Resources over HTTP in install-g-test
High
CVE-2016-10630
was published
for
install-g-test
(npm)
Feb 18, 2019
Downloads Resources over HTTP in limbus-buildgen
High
CVE-2016-10674
was published
for
limbus-buildgen
(npm)
Feb 18, 2019
Moderate severity vulnerability that affects handlebars
Moderate
GHSA-fmr4-7g9q-7hc7
was published
for
handlebars
(npm)
Oct 24, 2017
•
withdrawn
Critical severity vulnerability that affects Haraka
Critical
CVE-2016-1000282
was published
for
Haraka
(npm)
Feb 12, 2019
Downloads Resources over HTTP in phantomjs-cheniu
High
CVE-2016-10661
was published
for
phantomjs-cheniu
(npm)
Feb 18, 2019
Context isolation bypass via contextBridge in Electron
High
CVE-2020-4077
was published
for
electron
(npm)
Jul 7, 2020
Path Traversal in socket.io-file
High
CVE-2020-15779
was published
for
socket.io-file
(npm)
Jul 7, 2020
Downloads Resources over HTTP in mystem-wrapper
High
CVE-2016-10671
was published
for
mystem-wrapper
(npm)
Feb 18, 2019
Downloads Resources over HTTP in webdrvr
High
CVE-2016-10601
was published
for
webdrvr
(npm)
Feb 18, 2019
Downloads Resources over HTTP in pennyworth
High
CVE-2016-10619
was published
for
pennyworth
(npm)
Feb 18, 2019
Downloads Resources over HTTP in galenframework-cli
High
CVE-2016-10560
was published
for
galenframework-cli
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API