GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,909 advisories
Filter by severity
Security check skip in Apache Dubbo
Critical
CVE-2021-37579
was published
for
org.apache.dubbo:dubbo
(Maven)
Sep 10, 2021
XML Injection in Any23
Critical
CVE-2021-38555
was published
for
org.apache.any23:apache-any23
(Maven)
Sep 13, 2021
Remote Code Execution in Any23
Critical
CVE-2021-40146
was published
for
org.apache.any23:apache-any23
(Maven)
Sep 13, 2021
merge vulnerable to Prototype Pollution
Critical
CVE-2021-3645
was published
for
@viking04/merge
(npm)
Sep 13, 2021
UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable
Critical
GHSA-q4h9-46xg-m3x9
was published
for
@openzeppelin/contracts-upgradeable
(npm)
Sep 15, 2021
UUPSUpgradeable vulnerability in @openzeppelin/contracts
Critical
CVE-2021-41264
was published
for
@openzeppelin/contracts
(npm)
Sep 15, 2021
Lacking Protection against HTTP Request Smuggling in mitmproxy
Critical
CVE-2021-39214
was published
for
mitmproxy
(pip)
Sep 20, 2021
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Critical
CVE-2021-41303
was published
for
org.apache.shiro:shiro-core
(Maven)
Sep 20, 2021
Remote code execution in UReport
Critical
CVE-2020-21125
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Sep 20, 2021
Improper Control of Generation of Code ('Code Injection') in @asyncapi/modelina
Critical
CVE-2023-23619
was published
for
@asyncapi/modelina
(npm)
Sep 21, 2021
Remote Code Execution in Halibut
Critical
CVE-2021-31819
was published
for
Halibut
(NuGet)
Sep 23, 2021
Deno's static imports inside dynamically imported modules do not adhere to permission checks
Critical
CVE-2021-32619
was published
for
deno
(Rust)
Sep 23, 2021
Prototype pollution in aurelia-path
Critical
CVE-2021-41097
was published
for
aurelia-path
(npm)
Sep 27, 2021
Improper Access Control in Webauthn Framework
Critical
CVE-2021-38299
was published
for
web-auth/webauthn-framework
(Composer)
Sep 29, 2021
Directory Traversal in typo3/phar-stream-wrapper
Critical
CVE-2019-11831
was published
for
drupal/core
(Composer)
Sep 30, 2021
SQL Injection in topthink/thinkphp
Critical
CVE-2020-20120
was published
for
topthink/thinkphp
(Composer)
Sep 30, 2021
Deserialization of Untrusted Data in org.apache.ddlutils:ddlutils
Critical
CVE-2021-41616
was published
for
org.apache.ddlutils:ddlutils
(Maven)
Oct 4, 2021
Expression injection in AviatorScript
Critical
CVE-2021-41862
was published
for
com.googlecode.aviator:aviator
(Maven)
Oct 4, 2021
Remote code execution in ruby-jss
Critical
CVE-2021-33575
was published
for
ruby-jss
(RubyGems)
Oct 6, 2021
Prototype pollution in getobject
Critical
CVE-2020-28282
was published
for
getobject
(npm)
Oct 12, 2021
Prototype pollution vulnerability in 'libnested'
Critical
CVE-2020-28283
was published
for
libnested
(npm)
Oct 12, 2021
ProTip!
Advisories are also available from the
GraphQL API