GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,203
Maven
5,000+
npm
3,852
NuGet
696
pip
3,637
Pub
12
RubyGems
911
Rust
913
Swift
38
Unreviewed advisories
All unreviewed
5,000+
144 advisories
Filter by severity
Improper Input Validation in Google Closure Library
Moderate
CVE-2020-8910
was published
for
google-closure-library
(npm)
May 7, 2021
Improper Input Validation in sanitize-html
Moderate
CVE-2021-26540
was published
for
sanitize-html
(npm)
May 6, 2021
Improper Input Validation in sanitize-html
Moderate
CVE-2021-26539
was published
for
sanitize-html
(npm)
May 6, 2021
cumulative-distribution-function Infinite Loop vulnerability
High
CVE-2021-29486
was published
for
cumulative-distribution-function
(npm)
May 4, 2021
Improper parsing of octal bytes in netmask
Critical
CVE-2021-28918
was published
for
netmask
(npm)
Apr 14, 2021
Remote code execution in mongo-express
Critical
CVE-2020-24391
was published
for
mongodb-query-parser
(npm)
Apr 13, 2021
Improper Input Validation in SocksJS-Node
Moderate
CVE-2020-7693
was published
for
sockjs
(npm)
Apr 13, 2021
Improper Input Validation in network-manager
Critical
CVE-2019-10786
was published
for
network-manager
(npm)
Apr 13, 2021
netmask npm package mishandles octal input data
Moderate
CVE-2021-29418
was published
for
netmask
(npm)
Mar 29, 2021
Regular Expression Denial-of-Service in npm schema-inspector
High
CVE-2021-21267
was published
for
schema-inspector
(npm)
Mar 19, 2021
URIjs Hostname spoofing via backslashes in URL
High
CVE-2021-27516
was published
for
urijs
(npm)
Mar 1, 2021
Hostname spoofing via backslashes in URL
Moderate
CVE-2020-26291
was published
for
urijs
(npm)
Dec 30, 2020
ReDOS vulnerabities: multiple grammars
Moderate
GHSA-7wwv-vh3v-89cq
was published
for
@highlightjs/cdn-assets
(npm)
Dec 4, 2020
Prototype pollution in object-path
High
CVE-2020-15256
was published
for
object-path
(npm)
Oct 19, 2020
File restriction bypass in socket.io-file
High
GHSA-6495-8jvh-f28x
was published
for
socket.io-file
(npm)
Oct 2, 2020
Environment Variable Injection in GitHub Actions
Low
CVE-2020-15228
was published
for
@actions/core
(npm)
Oct 1, 2020
ProTip!
Advisories are also available from the
GraphQL API