Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

26,865 advisories

Loading
Malicious Package in wallet-address-validtaor Critical
GHSA-pc7q-c837-3wjq was published for wallet-address-validtaor (npm) Sep 3, 2020
Improper Authorization in passport-cognito Critical
CVE-2019-19723 was published for passport-cognito (npm) Sep 4, 2020
Malicious npm package: an0n-chat-lib Critical
GHSA-7xcv-wvr7-4h6p was published for an0n-chat-lib (npm) Jan 29, 2021
Malicious Package in riped160 Critical
GHSA-rwcq-qpm6-7867 was published for riped160 (npm) Sep 3, 2020
Malicious Package in crpyto-js Critical
GHSA-73c6-vwjh-g3qh was published for crpyto-js (npm) Sep 3, 2020
Malicious Package in bs58chcek Critical
GHSA-97mp-9g5c-6c93 was published for bs58chcek (npm) Sep 4, 2020
Malicious Package in hw-trnasport-u2f Critical
GHSA-4363-x42f-xph6 was published for hw-trnasport-u2f (npm) Sep 3, 2020
Malicious Package in ripedm160 Critical
GHSA-9272-59x2-gwf2 was published for ripedm160 (npm) Sep 3, 2020
Malicious Package in web3-eht Critical
GHSA-29fh-xcjr-p7rx was published for web3-eht (npm) Sep 3, 2020
Malicious Package in 1337qq-js Critical
GHSA-7wgh-5q4q-6wx5 was published for 1337qq-js (npm) Sep 4, 2020
Authentication Bypass in express-laravel-passport Critical
GHSA-v66p-w7qx-wv98 was published for express-laravel-passport (npm) Sep 4, 2020
Code injection in nobelprizeparser Critical
GHSA-4wv4-mgfq-598v was published for nobelprizeparser (npm) Mar 12, 2021
Malicious code in `loadyaml` Critical
GHSA-mfc2-93pr-jf92 was published for loadyaml (npm) Oct 1, 2020
Privilege Escalation in Kubernetes Critical
CVE-2018-1002105 was published for github.com/kubernetes/kubernetes (Go) Feb 15, 2022
After order payment process manipulation in shopware/platform and shopware/core Critical
GHSA-88rc-3p98-rgvx was published for shopware/core (Composer) Apr 13, 2021
Malicious npm package: sonatype Critical
GHSA-w8fh-pvq2-x8c4 was published for sonatype (npm) Jan 29, 2021
Malicious npm package: discord-fix Critical
GHSA-qv2g-99x4-45x6 was published for discord-fix (npm) Jan 29, 2021
Leak of information via Store-API Critical
GHSA-f2vv-h5x4-57gr was published for shopware/platform (Composer) Feb 10, 2021
Use after free in rio Critical
CVE-2020-35876 was published for rio (Rust) Aug 25, 2021
Denial of service in go-ethereum due to CVE-2020-28362 Critical
GHSA-m6gx-rhvj-fh52 was published for github.com/ethereum/go-ethereum (Go) Jun 29, 2021
Signature Validation Bypass Critical
GHSA-5684-g483-2249 was published for github.com/russellhaering/gosaml2 (Go) May 24, 2021
jupenur
Insecure Permissions in Gogs Critical
CVE-2019-14544 was published for gogs.io/gogs (Go) May 18, 2021
Leak of information via Store-API aggregations in shopware/platform and shopware/core Critical
GHSA-qg7c-q3vq-rgxr was published for shopware/core (Composer) Apr 13, 2021
Signature Validation Bypass Critical
GHSA-rrfw-hg9m-j47h was published for github.com/russellhaering/goxmldsig (Go) May 24, 2021
jupenur russellhaering
Improper Verification of Cryptographic Signature Critical
GHSA-7r96-8g3x-g36m was published for tenvoy (npm) Jun 28, 2021
ProTip! Advisories are also available from the GraphQL API