GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,019
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,296 advisories
Filter by severity
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7648
was published
for
snyk-broker
(npm)
Jun 3, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7653
was published
for
snyk-broker
(npm)
Jun 3, 2020
Http request which redirect to another hostname do not strip authorization header in @actions/http-client
Moderate
CVE-2020-11021
was published
for
@actions/http-client
(npm)
Apr 29, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7650
was published
for
snyk-broker
(npm)
Jun 3, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7651
was published
for
snyk-broker
(npm)
Jun 3, 2020
Uncaught exception in engine.io
Moderate
CVE-2022-41940
was published
for
engine.io
(npm)
Nov 21, 2022
No Charset in Content-Type Header in express
Moderate
CVE-2014-6393
was published
for
express
(npm)
Oct 23, 2018
node-red-dashboard vulnerable to Cross-site Scripting
Moderate
CVE-2022-3783
was published
for
node-red-dashboard
(npm)
Nov 1, 2022
Integer Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algorithm in bcrypt
Moderate
CVE-2020-7689
was published
for
bcrypt
(npm)
Aug 20, 2020
Cross-Site Scripting in @novnc/novnc
Moderate
CVE-2017-18635
was published
for
@novnc/novnc
(npm)
Aug 28, 2020
receiving subscription objects with deleted session
Moderate
CVE-2020-15270
was published
for
parse-server
(npm)
Oct 27, 2020
Prototype Pollution in highlight.js
Moderate
CVE-2020-26237
was published
for
highlight.js
(npm)
Nov 24, 2020
Command Injection in systeminformation
Moderate
CVE-2020-26300
was published
for
systeminformation
(npm)
Oct 27, 2020
Axios vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-28168
was published
for
axios
(npm)
Jan 4, 2021
Regular Expression Denial of Service (REDoS) in Marked
Moderate
CVE-2021-21306
was published
for
marked
(npm)
Feb 8, 2021
Cross-site Scripting in dompurify
Moderate
CVE-2020-26870
was published
for
dompurify
(npm)
Dec 18, 2020
Resource Exhaustion Denial of Service in http-proxy-agent
Moderate
CVE-2019-10196
was published
for
http-proxy-agent
(npm)
Jan 6, 2022
Improper Validation and Sanitization in url-parse
Moderate
CVE-2020-8124
was published
for
url-parse
(npm)
Jan 6, 2022
Regular expression Denial of Service in @progfay/scrapbox-parser
Moderate
CVE-2021-27405
was published
for
@progfay/scrapbox-parser
(npm)
Mar 1, 2021
ProTip!
Advisories are also available from the
GraphQL API