GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,865 advisories
Filter by severity
Malicious Package in wallet-address-validtaor
Critical
GHSA-pc7q-c837-3wjq
was published
for
wallet-address-validtaor
(npm)
Sep 3, 2020
Improper Authorization in passport-cognito
Critical
CVE-2019-19723
was published
for
passport-cognito
(npm)
Sep 4, 2020
Malicious npm package: an0n-chat-lib
Critical
GHSA-7xcv-wvr7-4h6p
was published
for
an0n-chat-lib
(npm)
Jan 29, 2021
Malicious Package in riped160
Critical
GHSA-rwcq-qpm6-7867
was published
for
riped160
(npm)
Sep 3, 2020
Malicious Package in crpyto-js
Critical
GHSA-73c6-vwjh-g3qh
was published
for
crpyto-js
(npm)
Sep 3, 2020
Malicious Package in bs58chcek
Critical
GHSA-97mp-9g5c-6c93
was published
for
bs58chcek
(npm)
Sep 4, 2020
Malicious Package in hw-trnasport-u2f
Critical
GHSA-4363-x42f-xph6
was published
for
hw-trnasport-u2f
(npm)
Sep 3, 2020
Malicious Package in ripedm160
Critical
GHSA-9272-59x2-gwf2
was published
for
ripedm160
(npm)
Sep 3, 2020
Malicious Package in web3-eht
Critical
GHSA-29fh-xcjr-p7rx
was published
for
web3-eht
(npm)
Sep 3, 2020
Malicious Package in 1337qq-js
Critical
GHSA-7wgh-5q4q-6wx5
was published
for
1337qq-js
(npm)
Sep 4, 2020
Authentication Bypass in express-laravel-passport
Critical
GHSA-v66p-w7qx-wv98
was published
for
express-laravel-passport
(npm)
Sep 4, 2020
Code injection in nobelprizeparser
Critical
GHSA-4wv4-mgfq-598v
was published
for
nobelprizeparser
(npm)
Mar 12, 2021
Malicious code in `loadyaml`
Critical
GHSA-mfc2-93pr-jf92
was published
for
loadyaml
(npm)
Oct 1, 2020
Privilege Escalation in Kubernetes
Critical
CVE-2018-1002105
was published
for
github.com/kubernetes/kubernetes
(Go)
Feb 15, 2022
After order payment process manipulation in shopware/platform and shopware/core
Critical
GHSA-88rc-3p98-rgvx
was published
for
shopware/core
(Composer)
Apr 13, 2021
Malicious npm package: sonatype
Critical
GHSA-w8fh-pvq2-x8c4
was published
for
sonatype
(npm)
Jan 29, 2021
Malicious npm package: discord-fix
Critical
GHSA-qv2g-99x4-45x6
was published
for
discord-fix
(npm)
Jan 29, 2021
Leak of information via Store-API
Critical
GHSA-f2vv-h5x4-57gr
was published
for
shopware/platform
(Composer)
Feb 10, 2021
Denial of service in go-ethereum due to CVE-2020-28362
Critical
GHSA-m6gx-rhvj-fh52
was published
for
github.com/ethereum/go-ethereum
(Go)
Jun 29, 2021
Signature Validation Bypass
Critical
GHSA-5684-g483-2249
was published
for
github.com/russellhaering/gosaml2
(Go)
May 24, 2021
Insecure Permissions in Gogs
Critical
CVE-2019-14544
was published
for
gogs.io/gogs
(Go)
May 18, 2021
Leak of information via Store-API aggregations in shopware/platform and shopware/core
Critical
GHSA-qg7c-q3vq-rgxr
was published
for
shopware/core
(Composer)
Apr 13, 2021
Signature Validation Bypass
Critical
GHSA-rrfw-hg9m-j47h
was published
for
github.com/russellhaering/goxmldsig
(Go)
May 24, 2021
Improper Verification of Cryptographic Signature
Critical
GHSA-7r96-8g3x-g36m
was published
for
tenvoy
(npm)
Jun 28, 2021
ProTip!
Advisories are also available from the
GraphQL API