GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,165 advisories
Filter by severity
Cross-site Scripting in jspwiki-war
Moderate
CVE-2018-20242
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Feb 12, 2019
grunt-gh-pages before 0.10.0 may allow unencrypted GitHub credentials to be written to a log file
Moderate
CVE-2016-10526
was published
for
grunt-gh-pages
(npm)
Feb 18, 2019
Directory Traversal in restafary
Moderate
CVE-2016-10528
was published
for
restafary
(npm)
Feb 18, 2019
Insecure Defaults Allow MITM Over TLS in engine.io-client
Moderate
CVE-2016-10536
was published
for
engine.io-client
(npm)
Feb 18, 2019
Cross-Site Scripting in backbone
Moderate
CVE-2016-10537
was published
for
backbone
(npm)
Feb 18, 2019
Downloads Resources over HTTP in arcanist
Moderate
CVE-2016-10683
was published
for
arcanist
(npm)
Feb 18, 2019
ipip downloads Resources over HTTP
Moderate
CVE-2016-10594
was published
for
ipip
(npm)
Feb 18, 2019
Downloads Resources over HTTP in jser-stat
Moderate
CVE-2016-10592
was published
for
jser-stat
(npm)
Feb 18, 2019
m-server Vulnerable to Directory Traversal
Moderate
CVE-2018-16485
was published
for
m-server
(npm)
Feb 18, 2019
Insecure Default Configuration in airbrake
Moderate
CVE-2016-10530
was published
for
airbrake
(npm)
Feb 18, 2019
Sanitization bypass using HTML Entities in marked
Moderate
CVE-2016-10531
was published
for
marked
(npm)
Feb 18, 2019
Bootstrap Vulnerable to Cross-Site Scripting
Moderate
CVE-2019-8331
was published
for
Bootstrap.Less
(RubyGems)
Feb 22, 2019
uap-core Regular Expression Denial of Service issue
Moderate
CVE-2018-20164
was published
for
uap-core
(npm)
Mar 6, 2019
Moderate severity vulnerability that affects org.b3log:symphony
Moderate
CVE-2019-9142
was published
for
org.b3log:symphony
(Maven)
Mar 6, 2019
Apache Airflow vulnerable to Stored XSS
Moderate
CVE-2018-20244
was published
for
apache-airflow
(pip)
Mar 6, 2019
Cross-Site Scripting in editor.md
Moderate
CVE-2019-9737
was published
for
editor.md
(npm)
Mar 14, 2019
Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
Moderate
CVE-2019-9658
was published
for
com.puppycrawl.tools:checkstyle
(Maven)
Mar 14, 2019
spring-security-oauth and spring-security-oauth2 Open Redirect vulnerability
Moderate
CVE-2019-3778
was published
for
org.springframework.security.oauth:spring-security-oauth
(Maven)
Mar 14, 2019
Moderate severity vulnerability that affects org.apache.hive:hive, org.apache.hive:hive-exec, and org.apache.hive:hive-service
Moderate
CVE-2017-12625
was published
for
org.apache.hive:hive
(Maven)
Mar 14, 2019
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark via crafted URL
Moderate
CVE-2018-8024
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Mar 14, 2019
Exposure of Sensitive Information to an Unauthorized Actor in Apache Spark
Moderate
CVE-2018-1334
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Mar 14, 2019
Apache Commons Compress vulnerable to denial of service due to infinite loop
Moderate
CVE-2018-1324
was published
for
com.liferay:com.liferay.portal.tools.bundle.support
(Maven)
Mar 14, 2019
ProTip!
Advisories are also available from the
GraphQL API