GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,016 advisories
Filter by severity
Vulnerability in crunch function leads to arbitrary code execution via filePath parameters
Critical
CVE-2020-36380
was published
for
aaptjs
(npm)
Nov 1, 2021
Prototype pollution vulnerability in 'patchmerge'
Critical
CVE-2021-25916
was published
for
patchmerge
(npm)
Oct 13, 2021
OS Command Injection in node-opencv
Critical
CVE-2019-10061
was published
for
opencv
(npm)
Oct 12, 2021
Prototype Pollution in config-handler
Critical
CVE-2021-23448
was published
for
config-handler
(npm)
Oct 12, 2021
Prototype pollution in object-hierarchy-access
Critical
CVE-2020-28270
was published
for
object-hierarchy-access
(npm)
Oct 12, 2021
SQL Injection and Cross-site Scripting in class-validator
Critical
CVE-2019-18413
was published
for
class-validator
(npm)
Oct 12, 2021
Prototype pollution vulnerability in 'deepref'
Critical
CVE-2020-28274
was published
for
deepref
(npm)
Oct 12, 2021
Prototype pollution vulnerability in 'predefine'
Critical
CVE-2020-28280
was published
for
predefine
(npm)
Oct 12, 2021
Prototype pollution vulnerability in 'libnested'
Critical
CVE-2020-28283
was published
for
libnested
(npm)
Oct 12, 2021
Prototype pollution in getobject
Critical
CVE-2020-28282
was published
for
getobject
(npm)
Oct 12, 2021
Prototype pollution in aurelia-path
Critical
CVE-2021-41097
was published
for
aurelia-path
(npm)
Sep 27, 2021
Improper Control of Generation of Code ('Code Injection') in @asyncapi/modelina
Critical
CVE-2023-23619
was published
for
@asyncapi/modelina
(npm)
Sep 21, 2021
UUPSUpgradeable vulnerability in @openzeppelin/contracts
Critical
CVE-2021-41264
was published
for
@openzeppelin/contracts
(npm)
Sep 15, 2021
UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable
Critical
GHSA-q4h9-46xg-m3x9
was published
for
@openzeppelin/contracts-upgradeable
(npm)
Sep 15, 2021
merge vulnerable to Prototype Pollution
Critical
CVE-2021-3645
was published
for
@viking04/merge
(npm)
Sep 13, 2021
Unsafe defaults in `remark-html`
Critical
CVE-2021-39199
was published
for
remark-html
(npm)
Sep 7, 2021
objection.js Prototype Pollution vulnerability
Critical
CVE-2021-3766
was published
for
objection
(npm)
Sep 7, 2021
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ZMarkdown
Critical
GHSA-2c83-wfv3-q25f
was published
for
rebber
(npm)
Sep 7, 2021
Incorrect version tags linked to external repository
Critical
GHSA-593v-wcqx-hq2w
was published
for
parse-server
(npm)
Sep 7, 2021
Prototype Pollution in merge-change
Critical
CVE-2021-23421
was published
for
merge-change
(npm)
Sep 1, 2021
Incorrect Authorization in serverless-offline
Critical
CVE-2021-38384
was published
for
serverless-offline
(npm)
Sep 1, 2021
TimelockController vulnerability in OpenZeppelin Contracts
Critical
CVE-2021-39168
was published
for
@openzeppelin/contracts-upgradeable
(npm)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API