GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,127 advisories
Filter by severity
Malicious Package in jajajejejiji
Critical
GHSA-rggq-f2wf-m6cp
was published
for
jajajejejiji
(npm)
Sep 2, 2020
Command Injection in samsung-remote
Critical
GHSA-xhjx-mfr6-9rr4
was published
for
samsung-remote
(npm)
Sep 1, 2020
NoSQL Injection in loopback-connector-mongodb
High
GHSA-hxwc-5vw9-2w4w
was published
for
loopback-connector-mongodb
(npm)
Sep 2, 2020
Arbitrary File Overwrite in decompress-zip
High
GHSA-73v8-v6g4-vrpm
was published
for
decompress-zip
(npm)
Sep 2, 2020
Downloads Resources over HTTP in aerospike
High
CVE-2016-10558
was published
for
aerospike
(npm)
Feb 18, 2019
Malicious Package in donotinstallthis
Critical
GHSA-73hr-6785-f5p8
was published
for
donotinstallthis
(npm)
Sep 2, 2020
Malicious Package in rimrafall
Critical
GHSA-8hq2-fcqm-39hq
was published
for
rimrafall
(npm)
Sep 2, 2020
Sensitive Data Exposure in loopback
Low
GHSA-724c-6vrf-99rq
was published
for
loopback
(npm)
Sep 2, 2020
Malicious Package in require-ports
Critical
GHSA-qj3g-wfr7-3cv7
was published
for
require-ports
(npm)
Sep 2, 2020
Malicious Package in uglyfi-js
Critical
GHSA-9xww-fwh9-95c5
was published
for
uglyfi-js
(npm)
Sep 2, 2020
Malicious Package in destroyer-of-worlds
Critical
GHSA-w3f3-4j22-2v3p
was published
for
destroyer-of-worlds
(npm)
Sep 2, 2020
Malicious Package in colour-string
Critical
GHSA-8mmf-qp7j-2w24
was published
for
colour-string
(npm)
Sep 2, 2020
Malicious Package in commmander
Critical
GHSA-q42c-rrp3-r3xm
was published
for
commmander
(npm)
Sep 11, 2020
Malicious Package in requst
Critical
GHSA-8qx4-r7fx-xc4v
was published
for
requst
(npm)
Sep 11, 2020
Malicious Package in carloprojectlesang
Critical
GHSA-qj2g-642f-4jrv
was published
for
carloprojectlesang
(npm)
Sep 2, 2020
Malicious Package in requets
Critical
GHSA-f3pc-c2gf-hvgw
was published
for
requets
(npm)
Sep 2, 2020
Malicious Package in requset
Critical
GHSA-w7wg-24g3-2c78
was published
for
requset
(npm)
Sep 2, 2020
Forgeable Public/Private Tokens in jwt-simple
Critical
CVE-2016-10555
was published
for
jwt-simple
(npm)
Nov 6, 2018
Cross-Site Scripting in node-red
High
GHSA-5g6j-8hv4-vfgj
was published
for
node-red
(npm)
Sep 11, 2020
Cross-Site Scripting in @berslucas/liljs
Moderate
GHSA-c53x-wwx2-pg96
was published
for
@berslucas/liljs
(npm)
Sep 3, 2020
Downloads Resources over HTTP in broccoli-closure
High
CVE-2016-10635
was published
for
broccoli-closure
(npm)
Feb 18, 2019
Remote Code Execution in electron
High
CVE-2018-1000006
was published
for
electron
(npm)
Jan 23, 2018
Denial of Service in node-sass
Moderate
GHSA-9v62-24cr-58cx
was published
for
node-sass
(npm)
Sep 11, 2020
ProTip!
Advisories are also available from the
GraphQL API