GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,495
Maven
5,000+
npm
4,138
NuGet
735
pip
3,945
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,139 advisories
Filter by severity
Command Injection in macaddress
Critical
CVE-2018-13797
was published
for
macaddress
(npm)
Sep 6, 2018
simplehttpserver allows directory traversal and file listing
High
CVE-2018-3787
was published
for
simplehttpserver
(npm)
Sep 6, 2018
Pandao editor.md vulnerable to XSS in IMG attributes
Moderate
CVE-2018-16330
was published
for
editor.md
(npm)
Sep 6, 2018
Directory Traversal in easyquick
Moderate
CVE-2017-16109
was published
for
easyquick
(npm)
Aug 29, 2018
Hijacked Environment Variables in proxy.js
Moderate
CVE-2017-16076
was published
for
proxy.js
(npm)
Aug 29, 2018
Regular Expression Denial of Service in timespan
High
CVE-2017-16115
was published
for
timespan
(npm)
Aug 29, 2018
Electron webPreferences vulnerability can be used to perform remote code execution
High
CVE-2018-15685
was published
for
electron
(npm)
Aug 23, 2018
Privilege Escalation due to Blind NoSQL Injection in flintcms
Critical
CVE-2018-3783
was published
for
flintcms
(npm)
Aug 21, 2018
Command Injection in git-dummy-commit
Critical
CVE-2018-3785
was published
for
git-dummy-commit
(npm)
Aug 21, 2018
Downloads Resources over HTTP in haxe3
High
CVE-2016-10688
was published
for
haxe3
(npm)
Aug 17, 2018
ProTip!
Advisories are also available from the
GraphQL API