Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

111,583 advisories

Loading
Prototype Pollution in flat-wrap High
GHSA-g7h8-p22m-2rvx was published for flat-wrap (npm) Sep 4, 2020
Denial of Service in subtext High
GHSA-5854-jvxx-2cg9 was published for subtext (npm) Sep 3, 2020
Prototype Pollution High
CVE-2020-8147 was published for utils-extend (npm) Sep 3, 2020
Denial of Service in @hapi/accept High
GHSA-9vrw-m88g-w75q was published for @hapi/accept (npm) Sep 3, 2020
Denial of Service in ammo High
GHSA-mg85-8mv5-ffjr was published for ammo (npm) Sep 3, 2020
Cross-Site Scripting in ngx-md High
GHSA-xr53-m937-jr9c was published for ngx-md (npm) Sep 3, 2020
Command Injection in jison High
CVE-2020-8178 was published for jison (npm) Oct 8, 2020 withdrawn
Edit template, Remote Code Execution (RCE) Vulnerability in Latest Release 4.4.0 High
CVE-2020-15277 was published for baserproject/basercms (Composer) Oct 30, 2020
Aquilao
Update bitlyshortener to >=0.5.0 to prevent generating some invalid short URLs High
GHSA-r82c-j4mq-5xfw was published for bitlyshortener (pip) Oct 27, 2020
Prototype Pollution in json-logic-js High
GHSA-m9hw-7xfv-wqg7 was published for json-logic-js (npm) Nov 12, 2020
Vulnerability in RPKI manifest validation High
GHSA-q76j-58cx-wp5v was published for net.ripe.rpki:rpki-validator-3 (Maven) Nov 13, 2020
Improper Authentication in hive:hive-exec High
CVE-2018-11777 was published for org.apache.hive:hive-exec (Maven) Nov 21, 2018
Uncontrolled Resource Consumption in spray-json High
CVE-2018-18854 was published for io.spray:spray-json_2.10 (Maven) Nov 9, 2018
Deserialization of Untrusted Data in swagger-parser High
CVE-2017-1000208 was published for io.swagger:swagger-codegen (Maven) Oct 19, 2018
Improper Authentication High
GHSA-qxx8-292g-2w66 was published for Microsoft.Bot.Connector (NuGet) Mar 8, 2021
Prototype Pollution in lodash.mergewith High
GHSA-779f-wgxg-qr8f was published for lodash.mergewith (npm) Sep 3, 2020
Prototype Pollution in lodash.mergewith High
GHSA-5947-m4fg-xhqg was published for lodash.mergewith (npm) Sep 3, 2020
Sandbox Breakout / Arbitrary Code Execution in notevil High
GHSA-7r5f-7qr4-pf6q was published for notevil (npm) Sep 3, 2020
Cross-Site Scripting in console-feed High
GHSA-g9wg-wq4f-2x5w was published for console-feed (npm) Sep 3, 2020
Prototype Pollution in lodash.merge High
GHSA-h726-x36v-rx45 was published for lodash.merge (npm) Sep 3, 2020
Authentication Bypass in otpauth High
GHSA-rmmc-8cqj-hfp3 was published for otpauth (npm) Sep 3, 2020
Cross-Site Scripting in markdown-to-jsx High
GHSA-ccrp-c664-8p4j was published for markdown-to-jsx (npm) Sep 3, 2020
.NET Core Information Disclosure High
CVE-2018-8292 was published for System.Net.Http (NuGet) Apr 21, 2021
Machine-In-The-Middle in airtable High
GHSA-jrj9-5qp6-2v8q was published for airtable (npm) Sep 3, 2020
Prototype Pollution in reggae High
GHSA-q9wr-gcjc-hq52 was published for reggae (npm) Sep 4, 2020
ProTip! Advisories are also available from the GraphQL API