GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,587 advisories
Filter by severity
Path Traversal in http-live-simulator
High
CVE-2018-16479
was published
for
http-live-simulator
(npm)
Feb 7, 2019
mcstatic directory traversal vulnerability
High
CVE-2018-16482
was published
for
mcstatic
(npm)
Feb 7, 2019
Authentication Bypass by Spoofing in express-cart
High
CVE-2018-16483
was published
for
express-cart
(npm)
Feb 7, 2019
Path Traversal in simplehttpserver
High
CVE-2018-16493
was published
for
static-resource-server
(npm)
Feb 7, 2019
Pylons Colander Denial of Service vulnerability
High
CVE-2017-18361
was published
for
colander
(pip)
Feb 7, 2019
Path Traversal in cordova-plugin-ionic-webview
High
CVE-2018-16202
was published
for
cordova-plugin-ionic-webview
(npm)
Feb 12, 2019
Uncontrolled Memory Consumption in Django
High
CVE-2019-6975
was published
for
Django
(pip)
Feb 12, 2019
Rendertron discloses absolute paths of files
High
CVE-2017-18355
was published
for
rendertron
(npm)
Feb 12, 2019
Exposure of Sensitive Information to an Unauthorized Actor in Hadoop
High
CVE-2018-1296
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Feb 12, 2019
chromedriver126 downloads Resources over HTTP
High
CVE-2016-10609
was published
for
chromedriver126
(npm)
Feb 18, 2019
Downloads Resources over HTTP in openframe-glslviewer
High
CVE-2016-10607
was published
for
openframe-glslviewer
(npm)
Feb 18, 2019
Downloads Resources over HTTP in air-sdk
High
CVE-2016-10603
was published
for
air-sdk
(npm)
Feb 18, 2019
Downloads Resources over HTTP in webdrvr
High
CVE-2016-10601
was published
for
webdrvr
(npm)
Feb 18, 2019
sauce-connect downloads Resources over HTTP
High
CVE-2016-10599
was published
for
sauce-connect
(npm)
Feb 18, 2019
Downloads Resources over HTTP in cobalt-cli
High
CVE-2016-10597
was published
for
cobalt-cli
(npm)
Feb 18, 2019
jdf-sass downloads Resources over HTTP
High
CVE-2016-10595
was published
for
jdf-sass
(npm)
Feb 18, 2019
Downloads Resources over HTTP in prince
High
CVE-2016-10591
was published
for
prince
(npm)
Feb 18, 2019
selenium-binaries downloads resources over HTTP
High
CVE-2016-10589
was published
for
selenium-binaries
(npm)
Feb 18, 2019
Downloads Resources over HTTP in wasdk
High
CVE-2016-10587
was published
for
wasdk
(npm)
Feb 18, 2019
Downloads Resources over HTTP in libxl
High
CVE-2016-10585
was published
for
libxl
(npm)
Feb 18, 2019
steroids downloads resources over HTTP
High
CVE-2016-10581
was published
for
steroids
(npm)
Feb 18, 2019
Downloads Resources over HTTP in kindlegen
High
CVE-2016-10575
was published
for
kindlegen
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API