GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,015 advisories
Filter by severity
Command injection in github-todos
Critical
CVE-2021-44684
was published
for
github-todos
(npm)
Dec 10, 2021
Prototype pollution in getobject
Critical
CVE-2020-28282
was published
for
getobject
(npm)
Oct 12, 2021
OS Command Injection in gulkp-styledocco
Critical
CVE-2020-7607
was published
for
gulp-styledocco
(npm)
May 7, 2021
OS Command Injection in gulp-tape
Critical
CVE-2020-7605
was published
for
gulp-tape
(npm)
May 7, 2021
pandora-doomsday is malware
Critical
CVE-2017-16127
was published
for
pandora-doomsday
(npm)
Sep 1, 2020
Heap Based Buffer Overflow in libyaml
Critical
CVE-2013-6393
was published
for
libyaml
(npm)
Aug 31, 2020
Prototype Pollution in irrelon-path and @irrelon/path
Critical
CVE-2020-7708
was published
for
@irrelon/path
(npm)
May 6, 2021
OS Command Injection in Locutus
Critical
CVE-2020-13619
was published
for
locutus
(npm)
Jul 26, 2021
Command Execution in windows-cpu
Critical
CVE-2017-1000219
was published
for
windows-cpu
(npm)
Sep 1, 2020
keycloak-connect and keycloak-js improperly handle invalid tokens
Critical
CVE-2017-7474
was published
for
keycloak-connect
(npm)
Nov 15, 2017
Command injection in ts-process-promises
Critical
CVE-2020-7784
was published
for
ts-process-promises
(npm)
Jan 13, 2021
Potential Command Injection in libnotify
Critical
CVE-2013-7381
was published
for
libnotify
(npm)
Aug 31, 2020
Arbitrary shell command execution in logkitty
Critical
CVE-2020-8149
was published
for
logkitty
(npm)
Jun 5, 2020
ejs is vulnerable to remote code execution due to weak input validation
Critical
CVE-2017-1000228
was published
for
ejs
(npm)
Nov 30, 2017
karma-mojo enables OS Command Injection
Critical
CVE-2020-7626
was published
for
karma-mojo
(npm)
Feb 10, 2022
Command Injection in nuance-gulp-build-common
Critical
CVE-2020-28430
was published
for
nuance-gulp-build-common
(npm)
Apr 13, 2021
•
withdrawn
push-dir Enables OS Command Injection
Critical
CVE-2019-10803
was published
for
push-dir
(npm)
Feb 9, 2022
RSA signature validation vulnerability on maleable encoded message in jsrsasign
Critical
CVE-2021-30246
was published
for
jsrsasign
(npm)
Apr 16, 2021
ProTip!
Advisories are also available from the
GraphQL API