GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
23,998 advisories
Filter by severity
Cryptographically Weak Pseudo-Random Number Generator (PRNG) in akka-actor
Critical
CVE-2018-16115
was published
for
com.typesafe.akka:akka-actor_2.11
(Maven)
Oct 22, 2018
Use of Insufficiently Random Values in penggle:kaptcha
Critical
CVE-2018-18531
was published
for
com.github.penggle:kaptcha
(Maven)
Oct 23, 2018
Unrestricted Upload of File with Dangerous Type in blueimp-file-upload
Critical
CVE-2018-9206
was published
for
blueimp-file-upload
(npm)
Oct 22, 2018
False-positive validity for NFT1 genesis transactions in SLPJS
Critical
CVE-2020-15130
was published
for
slpjs
(npm)
Jul 30, 2020
Potential Command Injection in hubot-scripts
Critical
CVE-2013-7378
was published
for
hubot-scripts
(npm)
Aug 31, 2020
Cross-Site Scripting in swagger-ui
Critical
CVE-2016-5682
was published
for
swagger-ui
(npm)
Sep 1, 2020
Authentication Bypass in console-io
Critical
CVE-2016-10532
was published
for
console-io
(npm)
Feb 18, 2019
Malicious Package in dossier
Critical
GHSA-c8h6-89q2-mgv8
was published
for
dossier
(npm)
Sep 1, 2020
Malicious Package in regenrator
Critical
GHSA-m5p4-7wf9-6w99
was published
for
regenrator
(npm)
Sep 1, 2020
Sensitive Data Exposure in msrcrypto
Critical
CVE-2018-8319
was published
for
msrcrypto
(npm)
Sep 10, 2018
Malicious Package in wepack-cli
Critical
GHSA-fpw3-x4xq-6vxq
was published
for
wepack-cli
(npm)
Sep 2, 2020
Malicious Package in jajajejejiji
Critical
GHSA-rggq-f2wf-m6cp
was published
for
jajajejejiji
(npm)
Sep 2, 2020
Malicious Package in commander-js
Critical
GHSA-2hqf-qqmq-pgpp
was published
for
commander-js
(npm)
Sep 2, 2020
Command Injection in samsung-remote
Critical
GHSA-xhjx-mfr6-9rr4
was published
for
samsung-remote
(npm)
Sep 1, 2020
Malicious Package in commnader
Critical
GHSA-855m-jchh-9qjc
was published
for
commnader
(npm)
Sep 2, 2020
Malicious Package in requst
Critical
GHSA-8qx4-r7fx-xc4v
was published
for
requst
(npm)
Sep 11, 2020
Malicious Package in colour-string
Critical
GHSA-8mmf-qp7j-2w24
was published
for
colour-string
(npm)
Sep 2, 2020
Malicious Package in requset
Critical
GHSA-w7wg-24g3-2c78
was published
for
requset
(npm)
Sep 2, 2020
Malicious Package in destroyer-of-worlds
Critical
GHSA-w3f3-4j22-2v3p
was published
for
destroyer-of-worlds
(npm)
Sep 2, 2020
Malicious Package in uglyfi-js
Critical
GHSA-9xww-fwh9-95c5
was published
for
uglyfi-js
(npm)
Sep 2, 2020
Malicious Package in rimrafall
Critical
GHSA-8hq2-fcqm-39hq
was published
for
rimrafall
(npm)
Sep 2, 2020
ProTip!
Advisories are also available from the
GraphQL API