GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,016 advisories
Filter by severity
Malicious Package in json-serializer
Critical
GHSA-7xfq-xh6v-4mrm
was published
for
json-serializer
(npm)
Sep 1, 2020
Malicious Package in freshdom
Critical
GHSA-8qm2-24qc-c4qg
was published
for
freshdom
(npm)
Sep 1, 2020
Malicious Package in dossier
Critical
GHSA-c8h6-89q2-mgv8
was published
for
dossier
(npm)
Sep 1, 2020
Malicious Package in dynamo-schema
Critical
GHSA-vp8g-53fw-r9f2
was published
for
dynamo-schema
(npm)
Sep 1, 2020
Malicious Package in css_transform_step
Critical
GHSA-4rx9-58m7-gr8w
was published
for
css_transform_step
(npm)
Sep 1, 2020
Malicious Package in css_transform_support
Critical
GHSA-45cp-hpc9-8347
was published
for
css_transform_support
(npm)
Sep 1, 2020
Malicious Package in cordova-plugin-china-picker
Critical
GHSA-x9gm-qxhh-rf75
was published
for
cordova-plugin-china-picker
(npm)
Sep 1, 2020
Malicious Package in coffee-project
Critical
GHSA-3fv6-q5xv-fhpw
was published
for
coffee-project
(npm)
Sep 1, 2020
Malicious Package in blingjs
Critical
GHSA-hfc6-79wv-5hpw
was published
for
blingjs
(npm)
Sep 1, 2020
Malicious Package in awesome_react_utility
Critical
GHSA-m25q-fwg4-9v2p
was published
for
awesome_react_utility
(npm)
Sep 1, 2020
Malicious Package in another-date-range-picker
Critical
GHSA-8rxg-9g6f-vq9p
was published
for
another-date-range-picker
(npm)
Sep 1, 2020
Malicious Package in another-date-picker
Critical
GHSA-2p62-c4rm-mr72
was published
for
another-date-picker
(npm)
Sep 1, 2020
Malicious Package in angular-material-sidenav-rnd
Critical
GHSA-qmxf-fxq7-w59f
was published
for
angular-material-sidenav-rnd
(npm)
Sep 1, 2020
Malicious Package in angular-bmap
Critical
GHSA-w8hg-mxvh-9h57
was published
for
angular-bmap
(npm)
Sep 1, 2020
Malicious Package in @impala/bmap
Critical
GHSA-c82c-8pjw-6829
was published
for
@impala/bmap
(npm)
Sep 1, 2020
pandora-doomsday is malware
Critical
CVE-2017-16127
was published
for
pandora-doomsday
(npm)
Sep 1, 2020
npm-script-demo is malware
Critical
CVE-2017-16128
was published
for
npm-script-demo
(npm)
Sep 1, 2020
Command Execution in windows-cpu
Critical
CVE-2017-1000219
was published
for
windows-cpu
(npm)
Sep 1, 2020
Unsafe eval() in summit allows arbitrary code execution
Critical
CVE-2017-16020
was published
for
summit
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
Critical
GHSA-g336-c7wv-8hp3
was published
for
swagger-ui
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
Critical
CVE-2016-5682
was published
for
swagger-ui
(npm)
Sep 1, 2020
ProTip!
Advisories are also available from the
GraphQL API