GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,015 advisories
Filter by severity
Malicious Package in load-from-cwd-or-npm
Critical
GHSA-jxf5-7x3j-8j9m
was published
for
load-from-cwd-or-npm
(npm)
Sep 3, 2020
Malicious Package in my-very-own-package
Critical
GHSA-crr2-ph72-c52g
was published
for
my-very-own-package
(npm)
Sep 3, 2020
Malicious Package in maybemaliciouspackage
Critical
GHSA-m9r7-q9fc-qwx5
was published
for
maybemaliciouspackage
(npm)
Sep 3, 2020
Malicious Package in ali-contributor
Critical
GHSA-h3m2-h22h-695r
was published
for
ali-contributor
(npm)
Sep 3, 2020
Malicious Package in node-buc
Critical
GHSA-x3m6-rprw-862w
was published
for
node-buc
(npm)
Sep 3, 2020
Malicious Package in hsf-clients
Critical
GHSA-g5q2-fcg9-j526
was published
for
hsf-clients
(npm)
Sep 3, 2020
Malicious Package in midway-dataproxy
Critical
GHSA-mq9h-cwc2-6j5r
was published
for
midway-dataproxy
(npm)
Sep 3, 2020
Malicious Package in qingting
Critical
GHSA-559q-92vx-xvjp
was published
for
qingting
(npm)
Sep 3, 2020
Malicious Package in soket.js
Critical
GHSA-x6gq-467r-hwcc
was published
for
soket.js
(npm)
Sep 1, 2020
Malicious Package in blingjs
Critical
GHSA-hfc6-79wv-5hpw
was published
for
blingjs
(npm)
Sep 1, 2020
Malicious Package in angular-material-sidenav-rnd
Critical
GHSA-qmxf-fxq7-w59f
was published
for
angular-material-sidenav-rnd
(npm)
Sep 1, 2020
Malicious Package in cordova-plugin-china-picker
Critical
GHSA-x9gm-qxhh-rf75
was published
for
cordova-plugin-china-picker
(npm)
Sep 1, 2020
Malicious Package in nginxbeautifier
Critical
GHSA-28xx-8j99-m32j
was published
for
nginxbeautifier
(npm)
Sep 1, 2020
Cross-Site Scripting in swagger-ui
Critical
CVE-2016-1000226
was published
for
swagger-ui
(npm)
Sep 1, 2020
False-positive validity for NFT1 genesis transactions
Critical
CVE-2020-15131
was published
for
slp-validate
(npm)
Jul 30, 2020
Arbitrary Code Execution in mathjs
Critical
CVE-2017-1001002
was published
for
mathjs
(npm)
Dec 18, 2017
Malicious Package in rpc-websocket
Critical
GHSA-x87g-rgrh-r6g3
was published
for
rpc-websocket
(npm)
Sep 3, 2020
Malicious Package in smartsearchwp
Critical
GHSA-fgp6-8g62-qx6w
was published
for
smartsearchwp
(npm)
Sep 3, 2020
Malicious Package in donotinstallthis
Critical
GHSA-73hr-6785-f5p8
was published
for
donotinstallthis
(npm)
Sep 2, 2020
Malicious Package in rimrafall
Critical
GHSA-8hq2-fcqm-39hq
was published
for
rimrafall
(npm)
Sep 2, 2020
ProTip!
Advisories are also available from the
GraphQL API