GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
301,790 advisories
Filter by severity
Malicious Package in uglyfi-js
Critical
GHSA-9xww-fwh9-95c5
was published
for
uglyfi-js
(npm)
Sep 2, 2020
Malicious Package in commmander
Critical
GHSA-q42c-rrp3-r3xm
was published
for
commmander
(npm)
Sep 11, 2020
Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies
Moderate
CVE-2016-8751
was published
for
org.apache.ranger:ranger
(Maven)
Oct 17, 2018
Downloads Resources over HTTP in broccoli-closure
High
CVE-2016-10635
was published
for
broccoli-closure
(npm)
Feb 18, 2019
OS Command Injection in craftercms:crafter-studio
High
CVE-2018-19907
was published
for
org.craftercms:crafter-studio
(Maven)
Dec 19, 2018
Malicious Package in rpc-websocket
Critical
GHSA-x87g-rgrh-r6g3
was published
for
rpc-websocket
(npm)
Sep 3, 2020
Remote Code Execution in electron
High
CVE-2018-1000006
was published
for
electron
(npm)
Jan 23, 2018
Moderate severity vulnerability that affects com.rabbitmq:amqp-client and org.springframework.amqp:spring-amqp
Moderate
CVE-2018-11087
was published
for
com.rabbitmq:amqp-client
(Maven)
Oct 18, 2018
Low severity vulnerability that affects org.apache.hive:hive-exec, org.apache.hive:hive, and org.apache.hive:hive-service
Low
CVE-2014-0228
was published
for
org.apache.hive:hive
(Maven)
Nov 21, 2018
Cross-Site Scripting in node-red
High
GHSA-5g6j-8hv4-vfgj
was published
for
node-red
(npm)
Sep 11, 2020
Cross-Site Scripting in @berslucas/liljs
Moderate
GHSA-c53x-wwx2-pg96
was published
for
@berslucas/liljs
(npm)
Sep 3, 2020
Malicious Package in smartsearchwp
Critical
GHSA-fgp6-8g62-qx6w
was published
for
smartsearchwp
(npm)
Sep 3, 2020
Denial of Service in node-sass
Moderate
GHSA-9v62-24cr-58cx
was published
for
node-sass
(npm)
Sep 11, 2020
Command Injection in wxchangba
Moderate
GHSA-j6v9-xgvh-f796
was published
for
wxchangba
(npm)
Sep 11, 2020
Improper Authentication in Keycloak
High
CVE-2018-14637
was published
for
org.keycloak:keycloak-core
(Maven)
Dec 21, 2018
Uncontrolled Resource Consumption in spray-json when parsing decimal digit fields
High
CVE-2018-18853
was published
for
io.spray:spray-json_2.10
(Maven)
Nov 9, 2018
Improper Restriction of Operations within the Bounds of a Memory Buffer in akka-http-core
High
CVE-2017-1000118
was published
for
com.typesafe.akka:akka-http-core_2.11
(Maven)
Oct 22, 2018
Server Side Request Forgery in svgSalamander
High
CVE-2017-5617
was published
for
com.kitfox.svg:svg-salamander
(Maven)
Oct 19, 2018
Arbitrary Code Execution in mathjs
Critical
CVE-2017-1001002
was published
for
mathjs
(npm)
Dec 18, 2017
DNN (aka DotNetNuke) has Remote Code Execution via a cookie
High
CVE-2017-9822
was published
for
DotNetNuke.Core
(NuGet)
Oct 16, 2018
Directory Traversal in restafary
Moderate
CVE-2016-10528
was published
for
restafary
(npm)
Feb 18, 2019
Command Injection in git-tags-remote
High
GHSA-gm9x-q798-hmr4
was published
for
git-tags-remote
(npm)
Jul 29, 2020
Authorization header is not sanitized in an error object in auth0
High
CVE-2020-15125
was published
for
auth0
(npm)
Jul 29, 2020
ProTip!
Advisories are also available from the
GraphQL API