GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,879 advisories
Filter by severity
Prototype Pollution in worksmith
Critical
CVE-2020-7725
was published
for
worksmith
(npm)
May 6, 2021
Prototype Pollution in safe-object2
Critical
CVE-2020-7726
was published
for
safe-object2
(npm)
May 6, 2021
Authentication bypass in MAGMI
Critical
CVE-2020-5777
was published
for
dweeves/magmi
(Composer)
May 6, 2021
SQL Injection in odata4j
Critical
CVE-2016-11024
was published
for
org.odata4j:odata4j-core
(Maven)
May 7, 2021
SQL Injection in odata4j
Critical
CVE-2016-11023
was published
for
org.odata4j:odata4j-core
(Maven)
May 7, 2021
Improper Authentication in Apache Shiro
Critical
CVE-2020-11989
was published
for
org.apache.shiro:shiro-core
(Maven)
May 7, 2021
Improper Authentication in Apache Shiro
Critical
CVE-2020-1957
was published
for
org.apache.shiro:shiro-core
(Maven)
May 7, 2021
SQL Injection in Apache SkyWalking
Critical
CVE-2020-13921
was published
for
org.apache.skywalking:oap-server
(Maven)
May 7, 2021
Improper Restriction of XML External Entity Reference in MPXJ
Critical
CVE-2020-25020
was published
for
net.sf.mpxj:mpxj
(Maven)
May 7, 2021
Deserialization of Untrusted Data in bson
Critical
CVE-2020-7610
was published
for
bson
(npm)
May 7, 2021
Command Injection in onion-oled-js
Critical
CVE-2021-23377
was published
for
onion-oled-js
(npm)
May 7, 2021
Command Injection in ps-visitor
Critical
CVE-2021-23374
was published
for
ps-visitor
(npm)
May 7, 2021
OS Command Injection in docker-compose-remote-api
Critical
CVE-2020-7606
was published
for
docker-compose-remote-api
(npm)
May 7, 2021
OS Command Injection in gulkp-styledocco
Critical
CVE-2020-7607
was published
for
gulp-styledocco
(npm)
May 7, 2021
OS Command Injection in gulp-tape
Critical
CVE-2020-7605
was published
for
gulp-tape
(npm)
May 7, 2021
OS Command Injection in gulp-scss-lint
Critical
CVE-2020-7601
was published
for
gulp-scss-lint
(npm)
May 7, 2021
OS Command Injection in closure-compiler-stream
Critical
CVE-2020-7603
was published
for
closure-compiler-stream
(npm)
May 7, 2021
OS Command Injection in node-prompt-here
Critical
CVE-2020-7602
was published
for
node-prompt-here
(npm)
May 7, 2021
OS Command Injection in pulverizr
Critical
CVE-2020-7604
was published
for
pulverizr
(npm)
May 7, 2021
TypeORM vulnerable to MAID and Prototype Pollution
Critical
CVE-2020-8158
was published
for
typeorm
(npm)
May 7, 2021
Incorrect Authorization in Apache Solr
Critical
CVE-2021-29943
was published
for
org.apache.solr:solr-parent
(Maven)
May 10, 2021
ProTip!
Advisories are also available from the
GraphQL API