GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,248
Erlang
31
GitHub Actions
21
Go
2,016
Maven
5,000+
npm
3,721
NuGet
662
pip
3,400
Pub
11
RubyGems
890
Rust
852
Swift
36
Unreviewed advisories
All unreviewed
5,000+
159 advisories
Filter by severity
Parse Server stores password in plain text
Low
CVE-2020-26288
was published
for
parse-server
(npm)
Dec 28, 2020
Denial of service in fast-csv
Low
CVE-2020-26256
was published
for
@fast-csv/parse
(npm)
Dec 8, 2020
Unprotected dynamically loaded chunks
Low
CVE-2020-15262
was published
for
webpack-subresource-integrity
(npm)
Oct 19, 2020
Regular Expression Denial of Service in npm-user-validate
Low
GHSA-xgh6-85xh-479p
was published
for
npm-user-validate
(npm)
Oct 16, 2020
Context isolation bypass in Electron
Low
CVE-2020-15215
was published
for
electron
(npm)
Oct 6, 2020
Environment Variable Injection in GitHub Actions
Low
CVE-2020-15228
was published
for
@actions/core
(npm)
Oct 1, 2020
Incorrect Calculation in bigint-money
Low
GHSA-9r3m-mhfm-39cm
was published
for
bigint-money
(npm)
Sep 11, 2020
The `size` option isn't honored after following a redirect in node-fetch
Low
CVE-2020-15168
was published
for
node-fetch
(npm)
Sep 10, 2020
personnummer/js vulnerable to Improper Input Validation
Low
GHSA-vpgc-7h78-gx8f
was published
for
personnummer
(npm)
Sep 4, 2020
Prototype Pollution in @hapi/hoek
Low
GHSA-22h7-7wwg-qmgg
was published
for
@hapi/hoek
(npm)
Sep 4, 2020
Information Exposure in type-graphql
Low
GHSA-xf64-2f9p-6pqq
was published
for
type-graphql
(npm)
Sep 4, 2020
Global node_modules Binary Overwrite in bin-links
Low
GHSA-v45m-2wcp-gg98
was published
for
bin-links
(npm)
Sep 4, 2020
Symlink reference outside of node_modules in bin-links
Low
GHSA-2mj8-pj3j-h362
was published
for
bin-links
(npm)
Sep 4, 2020
Arbitrary File Write in bin-links
Low
GHSA-gqf6-75v8-vr26
was published
for
bin-links
(npm)
Sep 4, 2020
Regular Expression Denial of Service in markdown
Low
GHSA-wx77-rp39-c6vg
was published
for
markdown
(npm)
Sep 4, 2020
Denial of Service in express-fileupload
Low
GHSA-q3w9-g74q-vp5f
was published
for
express-fileupload
(npm)
Sep 3, 2020
Denial of Service in apostrophe
Low
GHSA-pv6r-vchh-cxg9
was published
for
apostrophe
(npm)
Sep 3, 2020
Authorization Bypass in graphql-shield
Low
GHSA-hx78-272p-mqqh
was published
for
graphql-shield
(npm)
Sep 3, 2020
Denial of Service in grpc-ts-health-check
Low
GHSA-m86m-5m44-pc93
was published
for
grpc-ts-health-check
(npm)
Sep 3, 2020
Regular Expression Denial of Service in marked
Low
GHSA-ch52-vgq2-943f
was published
for
marked
(npm)
Sep 3, 2020
Sensitive Data Exposure in loopback
Low
GHSA-724c-6vrf-99rq
was published
for
loopback
(npm)
Sep 2, 2020
Cross-Site Scripting in express-cart
Low
GHSA-9pr3-7449-977r
was published
for
express-cart
(npm)
Sep 2, 2020
Command Injection in ascii-art
Low
GHSA-9hqj-38j2-5jgm
was published
for
ascii-art
(npm)
Sep 1, 2020
ProTip!
Advisories are also available from the
GraphQL API