Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,606 advisories

Loading
react-dev-utils on Windows vulnerable to Remote Code Execution High
CVE-2018-6342 was published for react-dev-utils (npm) Jan 4, 2019
Missing Origin Validation in webpack-dev-server High
CVE-2018-14732 was published for webpack-dev-server (npm) Jan 4, 2019
NikoRaisanen
Denial of Service in ethereumjs-vm High
CVE-2018-19183 was published for ethereumjs-vm (npm) Nov 21, 2018
Header Forgery in http-signature High
CVE-2017-16005 was published for http-signature (npm) Nov 9, 2018
sqlserver is malware High
CVE-2017-16055 was published for sqlserver (npm) Nov 9, 2018
windows-build-tools downloads Resources over HTTP High
CVE-2017-16003 was published for windows-build-tools (npm) Nov 9, 2018
XSS in Data URI in remarkable High
CVE-2017-16006 was published for remarkable (npm) Nov 9, 2018
Insufficient Error Handling in http-proxy High
CVE-2017-16014 was published for http-proxy (npm) Nov 9, 2018
Directory Traversal in hostr High
CVE-2017-16029 was published for hostr (npm) Nov 9, 2018
gruntcli is malware High
CVE-2017-16058 was published for gruntcli (npm) Nov 9, 2018
mssql-node is malware High
CVE-2017-16059 was published for mssql-node (npm) Nov 9, 2018
mssql.js is malware High
CVE-2017-16056 was published for mssql.js (npm) Nov 9, 2018
nodemssql is malware High
CVE-2017-16057 was published for nodemssql (npm) Nov 9, 2018
Prototype Pollution in cached-path-relative High
CVE-2018-16472 was published for cached-path-relative (npm) Nov 7, 2018
Insecure randomness in socket.io High
CVE-2017-16031 was published for socket.io (npm) Nov 7, 2018
Cross-Site Request Forgery (CSRF) in Auth0 High
CVE-2018-6874 was published for auth0-js (npm) Nov 6, 2018
Path Traversal in knightjs High
CVE-2018-16475 was published for knightjs (npm) Nov 6, 2018
node-tkinter is malware High
CVE-2017-16062 was published for node-tkinter (npm) Nov 1, 2018
tkinter is malware High
CVE-2017-16061 was published for tkinter (npm) Nov 1, 2018
Prototype Pollution in merge High
CVE-2018-16469 was published for merge (npm) Nov 1, 2018
Missing Origin Validation in parcel-bundler High
CVE-2018-14731 was published for parcel-bundler (npm) Oct 30, 2018
Private Data Disclosure in express-restify-mongoose High
CVE-2016-10533 was published for express-restify-mongoose (npm) Oct 23, 2018
tdunlap607
mongose is malware High
CVE-2017-16077 was published for mongose (npm) Oct 10, 2018
node-openssl is malware High
CVE-2017-16064 was published for node-openssl (npm) Oct 10, 2018
Denial of Service via malformed accept-encoding header in hapi High
CVE-2017-16013 was published for hapi (npm) Oct 9, 2018
ProTip! Advisories are also available from the GraphQL API