GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,499
Maven
5,000+
npm
4,138
NuGet
735
pip
3,945
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,177 advisories
Filter by severity
Apache Camel's Mail is vulnerable to path traversal
Moderate
CVE-2018-8041
was published
for
org.apache.camel:camel-mail
(Maven)
Oct 16, 2018
ZipSlip in org.apache.storm:storm-core
Moderate
CVE-2018-8008
was published
for
org.apache.storm:storm-core
(Maven)
Oct 16, 2018
DotNetZip Zip-Slip Vulnerability
Moderate
CVE-2018-1002205
was published
for
DotNetZip
(NuGet)
Oct 16, 2018
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
High
CVE-2016-9878
was published
for
org.springframework:spring-webmvc
(Maven)
Oct 4, 2018
Spark allows remote attackers to read arbitrary files via a .. (dot dot) in the URI
High
CVE-2016-9177
was published
for
com.sparkjava:spark-core
(Maven)
Oct 4, 2018
Directory Traversal in augustine
Moderate
CVE-2017-0930
was published
for
augustine
(npm)
Sep 18, 2018
simplehttpserver allows directory traversal and file listing
High
CVE-2018-3787
was published
for
simplehttpserver
(npm)
Sep 6, 2018
Directory Traversal in easyquick
Moderate
CVE-2017-16109
was published
for
easyquick
(npm)
Aug 29, 2018
Arbitrary File Write in adm-zip
Moderate
CVE-2018-1002204
was published
for
adm-zip
(npm)
Jul 27, 2018
Arbitrary File Write via Archive Extraction in unzipper
Moderate
CVE-2018-1002203
was published
for
unzipper
(npm)
Jul 27, 2018
Remote Code Execution in markdown-pdf
Moderate
CVE-2018-3770
was published
for
markdown-pdf
(npm)
Jul 27, 2018
Path Traversal in general-file-server
High
CVE-2018-3724
was published
for
general-file-server
(npm)
Jul 26, 2018
Path Traversal in angular-http-server
Moderate
CVE-2018-3713
was published
for
angular-http-server
(npm)
Jul 26, 2018
ProTip!
Advisories are also available from the
GraphQL API