GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,598 advisories
Filter by severity
Prototype Pollution in safe-object2
High
GHSA-qccf-q7p4-3q3j
was published
for
safe-object2
(npm)
Sep 4, 2020
Prototype Pollution in deep-setter
High
GHSA-9qrg-h9g8-c65q
was published
for
deep-setter
(npm)
Sep 4, 2020
Prototype Pollution in unflatten
High
GHSA-6fh5-8wq8-w3wr
was published
for
unflatten
(npm)
Sep 4, 2020
Prototype Pollution in flat-wrap
High
GHSA-g7h8-p22m-2rvx
was published
for
flat-wrap
(npm)
Sep 4, 2020
Sandbox Breakout / Arbitrary Code Execution in safe-eval
High
GHSA-9pcf-h8q9-63f6
was published
for
safe-eval
(npm)
Sep 3, 2020
Regular Expression Denial of Service in sql-injection
High
GHSA-hvxq-j2r4-4jm8
was published
for
sql-injection
(npm)
Sep 3, 2020
Prototype Pollution in lodash.defaultsdeep
High
GHSA-46fh-8fc5-xcwx
was published
for
lodash.defaultsdeep
(npm)
Sep 3, 2020
Path Traversal in file-static-server
High
GHSA-qjfh-xc44-rm9x
was published
for
file-static-server
(npm)
Sep 3, 2020
Command Injection in entitlements
High
GHSA-g8vp-6hv4-m67c
was published
for
entitlements
(npm)
Sep 11, 2020
SQL Injection in untitled-model
High
GHSA-hq8g-qq57-5275
was published
for
untitled-model
(npm)
Sep 11, 2020
Unauthorized File Access in atompm
High
GHSA-v86x-f47q-f7f4
was published
for
atompm
(npm)
Sep 11, 2020
Information Exposure in cordova-android
High
CVE-2016-6799
was published
for
cordova-android
(npm)
Sep 11, 2020
Authentication Bypass by Spoofing in express-cart
High
CVE-2018-16483
was published
for
express-cart
(npm)
Feb 7, 2019
Cross-Site Request Forgery (CSRF) in Auth0
High
CVE-2018-6874
was published
for
auth0-js
(npm)
Nov 6, 2018
Cross-Site Scripting in wangeditor
High
GHSA-g7mw-5cq6-fv82
was published
for
wangeditor
(npm)
Sep 2, 2020
ProTip!
Advisories are also available from the
GraphQL API