GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,296 advisories
Filter by severity
Passing in a non-string 'html' argument can lead to unsanitized output
Moderate
CVE-2021-32696
was published
for
striptags
(npm)
Jun 18, 2021
Regular Expression Denial of Service (ReDOS)
Moderate
CVE-2021-29060
was published
for
color-string
(npm)
Jun 22, 2021
Denial of Service in SheetsJS Pro
Moderate
CVE-2021-32013
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Improper file handling in matrix-react-sdk
Moderate
CVE-2021-32622
was published
for
matrix-react-sdk
(npm)
Feb 10, 2022
Privilege escalation: all users can access Admin-level API keys
Moderate
CVE-2021-39192
was published
for
ghost
(npm)
Jul 22, 2021
Regular Expression Denial of Service in path-parse
Moderate
CVE-2021-23343
was published
for
path-parse
(npm)
Aug 10, 2021
Cross-site Scripting in curly-bracket-parser
Moderate
CVE-2021-23416
was published
for
curly-bracket-parser
(npm)
Aug 10, 2021
Prototype Pollution in deepmergefn
Moderate
CVE-2021-23417
was published
for
deepmergefn
(npm)
Aug 10, 2021
Clipboard-based DOM-XSS
Moderate
CVE-2021-37700
was published
for
@github/paste-markdown
(npm)
Aug 12, 2021
Prototype Pollution in mootools
Moderate
CVE-2021-23432
was published
for
mootools
(npm)
Sep 2, 2021
Cross-site Scripting in file-upload-with-preview
Moderate
CVE-2021-23439
was published
for
file-upload-with-preview
(npm)
Sep 7, 2021
Uncontrolled Resource Consumption in transpile
Moderate
CVE-2021-23429
was published
for
transpile
(npm)
Sep 2, 2021
Script injection
Moderate
CVE-2021-32660
was published
for
@backstage/techdocs-common
(npm)
Jun 4, 2021
Path traversal
Moderate
CVE-2021-32662
was published
for
@backstage/techdocs-common
(npm)
Jun 4, 2021
Script injection
Moderate
CVE-2021-32661
was published
for
@backstage/plugin-techdocs
(npm)
Jun 4, 2021
Automatic room upgrade handling can be used maliciously to bridge a room non-consentually
Moderate
CVE-2021-32659
was published
for
matrix-appservice-bridge
(npm)
Jun 21, 2021
Cross-site Scripting in jsoneditor
Moderate
CVE-2020-23849
was published
for
jsoneditor
(npm)
Oct 12, 2021
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Moderate
CVE-2021-26272
was published
for
ckeditor4
(npm)
Oct 13, 2021
Missing Handler in @scandipwa/magento-scripts
Moderate
CVE-2021-32684
was published
for
@scandipwa/magento-scripts
(npm)
Jun 21, 2021
Cross-site Scripting in Mermaid
Moderate
CVE-2021-35513
was published
for
mermaid
(npm)
Dec 10, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32012
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
URL Redirection to Untrusted Site ('Open Redirect') in fastify-static
Moderate
CVE-2021-22963
was published
for
fastify-static
(npm)
Oct 5, 2021
ProTip!
Advisories are also available from the
GraphQL API