GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
956 advisories
Filter by severity
Improper Certificate Validation in EM-HTTP-Request
High
CVE-2020-13482
was published
for
em-http-request
(RubyGems)
May 24, 2021
Dependency Confusion in Bundler
High
CVE-2020-36327
was published
for
bundler
(RubyGems)
May 24, 2021
Improper certificate validation in em-imap
High
CVE-2020-13163
was published
for
em-imap
(RubyGems)
May 24, 2021
Puma's Keepalive Connections Causing Denial Of Service
High
CVE-2021-29509
was published
for
puma
(RubyGems)
May 18, 2021
Nokogiri updates packaged dependency on libxml2 from 2.9.10 to 2.9.12
Moderate
GHSA-7rrm-v45f-jp64
was published
for
nokogiri
(RubyGems)
May 17, 2021
Insecure path handling in Bundler
High
CVE-2019-3881
was published
for
bundler
(RubyGems)
May 10, 2021
Tempfile on Windows path traversal vulnerability
High
CVE-2021-28966
was published
for
tmpdir
(RubyGems)
May 6, 2021
Possible DoS Vulnerability in Action Controller Token Authentication
High
CVE-2021-22904
was published
for
actionpack
(RubyGems)
May 5, 2021
Action Pack contains Information Disclosure / Unintended Method Execution vulnerability
High
CVE-2021-22885
was published
for
actionpack
(RubyGems)
May 5, 2021
Possible Open Redirect Vulnerability in Action Pack
Moderate
CVE-2021-22903
was published
for
actionpack
(RubyGems)
May 5, 2021
Denial of Service in Action Dispatch
High
CVE-2021-22902
was published
for
actionpack
(RubyGems)
May 5, 2021
Gon gem lack of escaping certain input when outputting as JSON
Moderate
CVE-2020-25739
was published
for
gon
(RubyGems)
Apr 30, 2021
Pgsync Contains Cleartext Transmission of Sensitive Information
High
CVE-2021-31671
was published
for
pgsync
(RubyGems)
Apr 27, 2021
Improper Certificate Validation in oauth ruby gem
High
CVE-2016-11086
was published
for
oauth
(RubyGems)
Apr 22, 2021
Cross-Site Request Forgery (CSRF) in trestle-auth
High
CVE-2021-29435
was published
for
trestle-auth
(RubyGems)
Apr 13, 2021
Improper Certificate Validation in TweetStream
Moderate
CVE-2020-24393
was published
for
tweetstream
(RubyGems)
Apr 13, 2021
Improper Certificate Validation in Puppet
Moderate
CVE-2020-7942
was published
for
puppet
(RubyGems)
Apr 13, 2021
Cross-site scripting in actionpack
Moderate
CVE-2020-8264
was published
for
actionpack
(RubyGems)
Apr 7, 2021
Remote code execution in Kramdown
High
CVE-2021-28834
was published
for
kramdown
(RubyGems)
Mar 29, 2021
Improper Certificate Validation in twitter-stream
Moderate
CVE-2020-24392
was published
for
twitter-stream
(RubyGems)
Mar 29, 2021
Activerecord-session_store Vulnerable to Timing Attack
Moderate
CVE-2019-25025
was published
for
activerecord-session_store
(RubyGems)
Mar 9, 2021
Actionpack Open Redirect Vulnerability
Moderate
CVE-2021-22881
was published
for
actionpack
(RubyGems)
Mar 2, 2021
Active Record subject to Regular Expression Denial-of-Service (ReDoS)
High
CVE-2021-22880
was published
for
activerecord
(RubyGems)
Mar 2, 2021
ProTip!
Advisories are also available from the
GraphQL API