GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,122 advisories
Filter by severity
Path Traversal in statics-server
Moderate
CVE-2019-15596
was published
for
statics-server
(npm)
Mar 31, 2020
Information disclosure through error object in auth0.js
High
CVE-2020-5263
was published
for
auth0-js
(npm)
Apr 10, 2020
Cross-Site Scripting in sanitize-html
Moderate
CVE-2016-1000237
was published
for
sanitize-html
(npm)
Apr 16, 2020
Cross-Site Scripting (XSS) in Verdaccio
Moderate
CVE-2019-14772
was published
for
verdaccio
(npm)
May 29, 2019
Introspection in schema validation in Apollo Server
Moderate
GHSA-w42g-7vfc-xf37
was published
for
apollo-server
(npm)
Jun 5, 2020
Validation Bypass in slp-validate
Critical
CVE-2019-16761
was published
for
slp-validate
(npm)
Nov 15, 2019
Information disclosure in parse-server
High
CVE-2020-5251
was published
for
parse-server
(npm)
Mar 4, 2020
Withdrawn: ESLint dependencies are vulnerable (ReDoS and Prototype Pollution)
Moderate
GHSA-7fhm-mqm4-2wp7
was published
for
acorn
(npm)
Mar 13, 2020
•
withdrawn
CSRF and DNS Rebinding in Oasis
Moderate
CVE-2020-11003
was published
for
@fraction/oasis
(npm)
Apr 16, 2020
Prototype Pollution Protection Bypass in qs
High
CVE-2017-1000048
was published
for
qs
(npm)
Apr 30, 2020
Downloads Resources over HTTP in alto-saxophone
High
CVE-2016-10694
was published
for
alto-saxophone
(npm)
Jul 31, 2018
Resources Downloaded over Insecure Protocol in igniteui
Low
CVE-2016-10552
was published
for
igniteui
(npm)
Feb 18, 2019
Downloads Resources over HTTP in selenium-download
High
CVE-2016-10559
was published
for
selenium-download
(npm)
Feb 18, 2019
Regular Expression Denial of Service in websocket-extensions (NPM package)
High
CVE-2020-7662
was published
for
websocket-extensions
(npm)
Jun 5, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7652
was published
for
snyk-broker
(npm)
Jun 3, 2020
Downloads Resources over HTTP in selenium-standalone-painful
High
CVE-2016-10679
was published
for
selenium-standalone-painful
(npm)
Feb 18, 2019
Path Traversal in simplehttpserver
High
CVE-2018-16493
was published
for
static-resource-server
(npm)
Feb 7, 2019
Downloads Resources over HTTP in cmake
High
CVE-2016-10642
was published
for
cmake
(npm)
Aug 15, 2018
Downloads Resources over HTTP in grunt-webdriver-qunit
High
CVE-2016-10606
was published
for
grunt-webdriver-qunit
(npm)
Feb 18, 2019
Downloads Resources over HTTP in bkjs-wand
High
CVE-2016-10571
was published
for
bkjs-wand
(npm)
Feb 18, 2019
Arbitrary JavaScript Execution in bassmaster
Critical
CVE-2014-7205
was published
for
bassmaster
(npm)
Oct 24, 2017
Authentication bypass via incorrect XML canonicalization and DOM traversal in saml2-js
Moderate
CVE-2017-11429
was published
for
saml2-js
(npm)
Jul 5, 2019
Downloads Resources over HTTP in selenium-portal
High
CVE-2016-10667
was published
for
selenium-portal
(npm)
Feb 18, 2019
Downloads Resources over HTTP in google-closure-tools-latest
High
CVE-2016-10677
was published
for
google-closure-tools-latest
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API