Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

111,584 advisories

Loading
Command Injection in tomato High
GHSA-wqhw-frpx-5mmp was published for tomato (npm) Sep 2, 2020
Cross-Site Scripting in wangeditor High
GHSA-g7mw-5cq6-fv82 was published for wangeditor (npm) Sep 2, 2020
Cross-Site Scripting in jquery-mobile High
GHSA-fj93-7wm4-8x2g was published for jquery-mobile (npm) Sep 2, 2020
Authentication Bypass by Spoofing in express-cart High
CVE-2018-16483 was published for express-cart (npm) Feb 7, 2019
Unexpected database bindings High
GHSA-x7p5-p2c9-phvg was published for illuminate/database (Composer) Feb 2, 2021
Cross-Site Request Forgery (CSRF) in Auth0 High
CVE-2018-6874 was published for auth0-js (npm) Nov 6, 2018
Prototype Pollution in lodash.defaultsdeep High
GHSA-46fh-8fc5-xcwx was published for lodash.defaultsdeep (npm) Sep 3, 2020
Path Traversal in ponse High
GHSA-wfhx-6pcm-7m55 was published for ponse (npm) Sep 3, 2020
/user/sessions endpoint allows detecting valid accounts High
GHSA-7vwg-39h8-8qp8 was published for ezsystems/ezplatform-rest (Composer) Mar 11, 2021
Path Traversal in file-static-server High
GHSA-qjfh-xc44-rm9x was published for file-static-server (npm) Sep 3, 2020
SQL Injection in resquel High
GHSA-crpm-fm48-chj7 was published for resquel (npm) Sep 11, 2020
Unauthorized File Access in atompm High
GHSA-v86x-f47q-f7f4 was published for atompm (npm) Sep 11, 2020
Information Exposure in cordova-android High
CVE-2016-6799 was published for cordova-android (npm) Sep 11, 2020
Path Traversal in serve High
GHSA-48gc-5j93-5cfq was published for serve (npm) Sep 11, 2020
Prototype Pollution in mithril High
GHSA-c3px-v9c7-m734 was published for mithril (npm) Sep 3, 2020
Command Injection in entitlements High
GHSA-g8vp-6hv4-m67c was published for entitlements (npm) Sep 11, 2020
SQL Injection in untitled-model High
GHSA-hq8g-qq57-5275 was published for untitled-model (npm) Sep 11, 2020
Regular Expression Denial of Service in sql-injection High
GHSA-hvxq-j2r4-4jm8 was published for sql-injection (npm) Sep 3, 2020
Sandbox Breakout / Arbitrary Code Execution in safe-eval High
GHSA-9pcf-h8q9-63f6 was published for safe-eval (npm) Sep 3, 2020
Cross-Site Scripting in eco High
GHSA-r32x-jhw5-g48p was published for eco (npm) Sep 3, 2020
Cross-site scripting in eZ Platform Kernel High
GHSA-mrvj-7q4f-5p42 was published for ezsystems/ezplatform-kernel (Composer) Mar 19, 2021
Prototype Pollution in unflatten High
GHSA-6fh5-8wq8-w3wr was published for unflatten (npm) Sep 4, 2020
Prototype Pollution in flat-wrap High
GHSA-g7h8-p22m-2rvx was published for flat-wrap (npm) Sep 4, 2020
Cross-Site Scripting in react High
GHSA-hg79-j56m-fxgv was published for react (npm) Sep 4, 2020
apostolos
Prototype Pollution in safe-object2 High
GHSA-qccf-q7p4-3q3j was published for safe-object2 (npm) Sep 4, 2020
ProTip! Advisories are also available from the GraphQL API