GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,296 advisories
Filter by severity
Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript
Moderate
GHSA-h45p-w933-jxh3
was published
for
@aws-crypto/client-browser
(npm)
Jun 1, 2021
Arbitrary Command Injection due to Improper Command Sanitization
Moderate
GHSA-hxwm-x553-x359
was published
for
@npmcli/git
(npm)
Aug 5, 2021
Regular Expression Denial of Service in millisecond
Moderate
GHSA-m489-xr35-fjxr
was published
for
millisecond
(npm)
Sep 22, 2021
GovernorCompatibilityBravo incorrect ABI encoding may lead to unexpected behavior
Moderate
GHSA-m6w8-fq7v-ph4m
was published
for
@openzeppelin/contracts
(npm)
Jan 13, 2022
Improper Privilege Management in shelljs
Moderate
GHSA-64g7-mvw6-v9qj
was published
for
shelljs
(npm)
Jan 14, 2022
Inefficient Regular Expression Complexity in Validator.js
Moderate
GHSA-xx4c-jj58-r7x6
was published
for
validator
(npm)
Nov 19, 2021
Marked ReDoS due to email addresses being evaluated in quadratic time
Moderate
GHSA-xf5p-87ch-gxw2
was published
for
marked
(npm)
Jun 5, 2019
grunt-gh-pages before 0.10.0 may allow unencrypted GitHub credentials to be written to a log file
Moderate
CVE-2016-10526
was published
for
grunt-gh-pages
(npm)
Feb 18, 2019
Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript
Moderate
CVE-2019-16763
was published
for
pannellum
(npm)
Nov 22, 2019
mysql Node.JS Module Vulnerable to Remote Memory Exposure
Moderate
GHSA-5f7m-mmpc-qhh4
was published
for
mysql
(npm)
May 23, 2019
cookie-signature Timing Attack
Moderate
CVE-2016-1000236
was published
for
cookie-signature
(npm)
Jan 6, 2020
Path traversal for local publishers in TechDocs backend
Moderate
GHSA-4jqc-jvh2-pxg9
was published
for
@backstage/plugin-techdocs-node
(npm)
Jun 17, 2022
Regular Expression Denial of Service in slug
Moderate
CVE-2017-16117
was published
for
slug
(npm)
Jul 24, 2018
Captcha Bypass in strapi-plugin-ezforms
Moderate
GHSA-8mgq-6r2q-82w9
was published
for
strapi-plugin-ezforms
(npm)
Aug 30, 2022
Cleartext Transmission of Sensitive Information in moment-timezone
Moderate
GHSA-v78c-4p63-2j6c
was published
for
moment-timezone
(npm)
Aug 30, 2022
mel-spintax has Inefficient Regular Expression Complexity
Moderate
CVE-2018-25077
was published
for
mel-spintax
(npm)
Jan 18, 2023
uap-core Regular Expression Denial of Service issue
Moderate
CVE-2018-20164
was published
for
uap-core
(npm)
Mar 6, 2019
@builder.io/qwik vulnerable to Cross-site Scripting
Moderate
CVE-2023-0410
was published
for
@builder.io/qwik
(npm)
Jan 20, 2023
Improper Input Validation in url-js
Moderate
CVE-2022-25839
was published
for
url-js
(npm)
Mar 12, 2022
Spoofing attack in swagger-ui-dist
Moderate
CVE-2021-46708
was published
for
swagger-ui-dist
(npm)
Mar 12, 2022
Sudden swap of user auth tokens in Volto
Moderate
CVE-2022-24740
was published
for
@plone/volto
(npm)
Mar 14, 2022
Cross-site Scripting in sanitize-url
Moderate
CVE-2021-23648
was published
for
@braintree/sanitize-url
(npm)
Mar 17, 2022
yargs-parser Vulnerable to Prototype Pollution
Moderate
CVE-2020-7608
was published
for
yargs-parser
(npm)
Sep 4, 2020
parse-server new anonymous user session acts as if it's created with password
Moderate
CVE-2021-39138
was published
for
parse-server
(npm)
Aug 23, 2021
ProTip!
Advisories are also available from the
GraphQL API