GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
956 advisories
Filter by severity
Doorkeeper vulnerable to Cross-site Request Forgery
Moderate
CVE-2014-8144
was published
for
doorkeeper
(RubyGems)
Sep 17, 2018
Moderate severity vulnerability that affects actionpack
Moderate
GHSA-m53f-rhq8-q6hf
was published
for
actionpack
(RubyGems)
Sep 17, 2018
•
withdrawn
Moderate severity vulnerability that affects actionpack
Moderate
GHSA-5xmj-wm96-fmw8
was published
for
actionpack
(RubyGems)
Sep 17, 2018
•
withdrawn
Moderate severity vulnerability that affects actionpack
Moderate
GHSA-23v3-qfrj-wmgh
was published
for
actionpack
(RubyGems)
Sep 17, 2018
•
withdrawn
Moderate severity vulnerability that affects actionpack
Moderate
GHSA-qf5x-qgx7-437h
was published
for
actionpack
(RubyGems)
Sep 17, 2018
•
withdrawn
Denial of service or RCE from libxml2 and libxslt
High
CVE-2015-8806
was published
for
nokogiri
(RubyGems)
Sep 17, 2018
Moderate severity vulnerability that affects actionpack
Moderate
GHSA-544j-77x9-h938
was published
for
actionpack
(RubyGems)
Sep 17, 2018
•
withdrawn
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14042
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14041
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
Critical
CVE-2018-1000544
was published
for
rubyzip
(RubyGems)
Sep 6, 2018
Ruby-ffi has a DLL loading issue
High
CVE-2018-1000201
was published
for
ffi
(RubyGems)
Aug 31, 2018
ember-source vulnerable to Cross-site Scripting
Moderate
CVE-2015-1866
was published
for
ember-source
(RubyGems)
Aug 28, 2018
Spina gem vulnerable to Cross-site request forgery (CSRF) vulnerability
High
CVE-2015-4619
was published
for
spina
(RubyGems)
Aug 28, 2018
Tinfoil Devise-two-factor does not "burn" a successfully validated one-time password (OTP)
Moderate
CVE-2015-7225
was published
for
devise-two-factor
(RubyGems)
Aug 28, 2018
Gollum Exposure of Sensitive Information
Moderate
CVE-2015-7314
was published
for
gollum
(RubyGems)
Aug 28, 2018
ember-source Cross-site Scripting vulnerability
Low
CVE-2014-0046
was published
for
ember-source
(RubyGems)
Aug 28, 2018
ember-source Cross-site Scripting vulnerability
Moderate
CVE-2015-7565
was published
for
ember-source
(RubyGems)
Aug 28, 2018
Nokogiri does not forbid namespace nodes in XPointer ranges
Critical
CVE-2016-4658
was published
for
nokogiri
(RubyGems)
Aug 21, 2018
High severity vulnerability that affects activerecord
High
GHSA-hm48-76wh-q86v
was published
for
activerecord
(RubyGems)
Aug 21, 2018
•
withdrawn
Nokogiri subject to DoS via libxml2 vulnerability
High
CVE-2015-5312
was published
for
nokogiri
(RubyGems)
Aug 21, 2018
High severity vulnerability that affects espeak-ruby
High
GHSA-w655-w578-99pq
was published
for
espeak-ruby
(RubyGems)
Aug 21, 2018
•
withdrawn
Ruby-saml allows attackers to perform XML signature wrapping attacks
High
CVE-2016-5697
was published
for
ruby-saml
(RubyGems)
Aug 21, 2018
Phusion Passenger uses a known /tmp filename
High
CVE-2016-10345
was published
for
passenger
(RubyGems)
Aug 21, 2018
Moderate severity vulnerability that affects archive-tar-minitar and minitar
Moderate
GHSA-cwp3-834g-x79g
was published
for
archive-tar-minitar
(RubyGems)
Aug 21, 2018
•
withdrawn
Git-fastclone passes user modifiable strings directly to a shell command
Critical
CVE-2015-8969
was published
for
git-fastclone
(RubyGems)
Aug 15, 2018
ProTip!
Advisories are also available from the
GraphQL API