GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,172 advisories
Filter by severity
Internal exception message exposure for login action in Sylius
Low
CVE-2019-16768
was published
for
sylius/sylius
(Composer)
Dec 5, 2019
SilverStripe Priviledge escalation through cache pollution
Low
CVE-2019-12617
was published
for
silverstripe/framework
(Composer)
Nov 12, 2019
Low severity vulnerability that affects eye.js
Low
GHSA-mgv2-57vj-99xc
was published
for
eye.js
(npm)
Oct 7, 2019
Malicious URL drafting attack against iodines static file server may allow path traversal
Low
CVE-2024-22050
was published
for
iodine
(RubyGems)
Oct 7, 2019
Low severity vulnerability that affects smartbanner.js
Low
GHSA-9mrq-cjgh-32g2
was published
for
smartbanner.js
(npm)
Sep 13, 2019
Undefined Behavior in sailsjs-cacheman
Low
GHSA-5w65-6875-rhq8
was published
for
sailsjs-cacheman
(npm)
Sep 11, 2019
Low severity vulnerability that affects Gw2Sharp
Low
GHSA-4vr3-9v7h-5f8v
was published
for
Gw2Sharp
(NuGet)
Jun 18, 2019
express-basic-auth Timing Attack due to native string comparison instead of constant time string comparison
Low
GHSA-c35v-qwqg-87jc
was published
for
express-basic-auth
(npm)
Jun 6, 2019
Regular Expression Denial of Service in braces
Low
GHSA-g95f-p29q-9xw4
was published
for
braces
(npm)
Jun 6, 2019
Regular Expression Denial of Service in clean-css
Low
GHSA-wxhq-pm8v-cw75
was published
for
clean-css
(npm)
Jun 5, 2019
Sensitive Data Exposure in sequelize-cli
Low
GHSA-3xc7-xg67-pw99
was published
for
sequelize-cli
(npm)
Jun 5, 2019
ircdkit vulnerable to Denial of Service due to unhandled connection end event
Low
GHSA-f7r3-p866-q9qr
was published
for
ircdkit
(npm)
Jun 3, 2019
Insecure Credential Storage in web3
Low
GHSA-27v7-qhfv-rqq8
was published
for
web3
(npm)
May 30, 2019
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Ratpack
Low
CVE-2019-11808
was published
for
io.ratpack:ratpack-groovy
(Maven)
May 14, 2019
SSL Validation Defaults to False in electron-packager
Low
CVE-2016-10534
was published
for
electron-packager
(npm)
Feb 18, 2019
Resources Downloaded over Insecure Protocol in igniteui
Low
CVE-2016-10552
was published
for
igniteui
(npm)
Feb 18, 2019
Regular Expression Denial of Service in jadedown
Low
CVE-2016-10520
was published
for
jadedown
(npm)
Feb 18, 2019
Low severity vulnerability that affects org.springframework.batch:spring-batch-core
Low
CVE-2019-3774
was published
for
org.springframework.batch:spring-batch-core
(Maven)
Jan 25, 2019
Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
Low
CVE-2019-3772
was published
for
org.springframework.integration:spring-integration-ws
(Maven)
Jan 25, 2019
ProTip!
Advisories are also available from the
GraphQL API