Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,296 advisories

Loading
Denial of service in Valine Moderate
CVE-2021-34801 was published for valine (npm) Jun 21, 2021
Passing in a non-string 'html' argument can lead to unsanitized output Moderate
CVE-2021-32696 was published for striptags (npm) Jun 18, 2021
erik-krogh
Regular Expression Denial of Service (ReDOS) Moderate
CVE-2021-29060 was published for color-string (npm) Jun 22, 2021
Denial of Service in SheetsJS Pro Moderate
CVE-2021-32013 was published for org.webjars.npm:xlsx (Maven) Jul 22, 2021
Improper file handling in matrix-react-sdk Moderate
CVE-2021-32622 was published for matrix-react-sdk (npm) Feb 10, 2022
Privilege escalation: all users can access Admin-level API keys Moderate
CVE-2021-39192 was published for ghost (npm) Jul 22, 2021
zn9988
Regular Expression Denial of Service in path-parse Moderate
CVE-2021-23343 was published for path-parse (npm) Aug 10, 2021
Cross-site Scripting in curly-bracket-parser Moderate
CVE-2021-23416 was published for curly-bracket-parser (npm) Aug 10, 2021
Prototype Pollution in deepmergefn Moderate
CVE-2021-23417 was published for deepmergefn (npm) Aug 10, 2021
Clipboard-based DOM-XSS Moderate
CVE-2021-37700 was published for @github/paste-markdown (npm) Aug 12, 2021
bananabr
Prototype Pollution in mootools Moderate
CVE-2021-23432 was published for mootools (npm) Sep 2, 2021
XSS in svg2png (NPM package) Moderate
CVE-2020-11887 was published for svg2png (npm) Jan 6, 2022
Cross-site Scripting in file-upload-with-preview Moderate
CVE-2021-23439 was published for file-upload-with-preview (npm) Sep 7, 2021
Uncontrolled Resource Consumption in transpile Moderate
CVE-2021-23429 was published for transpile (npm) Sep 2, 2021
Prototype Pollution in jointjs Moderate
CVE-2021-23444 was published for jointjs (npm) Sep 22, 2021
Script injection Moderate
CVE-2021-32660 was published for @backstage/techdocs-common (npm) Jun 4, 2021
Path traversal Moderate
CVE-2021-32662 was published for @backstage/techdocs-common (npm) Jun 4, 2021
Script injection Moderate
CVE-2021-32661 was published for @backstage/plugin-techdocs (npm) Jun 4, 2021
Automatic room upgrade handling can be used maliciously to bridge a room non-consentually Moderate
CVE-2021-32659 was published for matrix-appservice-bridge (npm) Jun 21, 2021
Cross-site Scripting in jsoneditor Moderate
CVE-2020-23849 was published for jsoneditor (npm) Oct 12, 2021
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4 Moderate
CVE-2021-26272 was published for ckeditor4 (npm) Oct 13, 2021
Missing Handler in @scandipwa/magento-scripts Moderate
CVE-2021-32684 was published for @scandipwa/magento-scripts (npm) Jun 21, 2021
Cross-site Scripting in Mermaid Moderate
CVE-2021-35513 was published for mermaid (npm) Dec 10, 2021
Denial of Service in SheetJS Pro Moderate
CVE-2021-32012 was published for org.webjars.npm:xlsx (Maven) Jul 22, 2021
URL Redirection to Untrusted Site ('Open Redirect') in fastify-static Moderate
CVE-2021-22963 was published for fastify-static (npm) Oct 5, 2021
ProTip! Advisories are also available from the GraphQL API