GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,109
Maven
5,000+
npm
3,764
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
887
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,469 advisories
Filter by severity
Denial of Service in mqtt-packet
High
CVE-2016-10523
was published
for
mqtt-packet
(npm)
Feb 18, 2019
Downloads Resources over HTTP in co-cli-installer
High
CVE-2016-10657
was published
for
co-cli-installer
(npm)
Feb 18, 2019
Downloads Resources over HTTP in fis-parser-sass-bin
High
CVE-2016-10660
was published
for
fis-parser-sass-bin
(npm)
Feb 18, 2019
Downloads Resources over HTTP in tomita
High
CVE-2016-10662
was published
for
tomita
(npm)
Feb 18, 2019
Keystone is vulnerable to CSV injection
High
CVE-2017-15879
was published
for
keystone
(npm)
Nov 16, 2017
Downloads Resources over HTTP in air-sdk
High
CVE-2016-10603
was published
for
air-sdk
(npm)
Feb 18, 2019
High severity vulnerability that affects electron
High
CVE-2016-1202
was published
for
electron
(npm)
Oct 24, 2017
Downloads Resources over HTTP in kindlegen
High
CVE-2016-10575
was published
for
kindlegen
(npm)
Feb 18, 2019
Downloads Resources over HTTP in healthcenter
High
CVE-2016-10684
was published
for
healthcenter
(npm)
Feb 18, 2019
Downloads Resources over HTTP in macaca-chromedriver
High
CVE-2016-10586
was published
for
macaca-chromedriver
(npm)
Feb 18, 2019
Downloads Resources over HTTP in unicode-json
High
CVE-2016-10610
was published
for
unicode-json
(npm)
Feb 18, 2019
Downloads Resources over HTTP in mystem-fix
High
CVE-2016-10698
was published
for
mystem-fix
(npm)
Jul 27, 2018
Downloads Resources over HTTP in libxl
High
CVE-2016-10585
was published
for
libxl
(npm)
Feb 18, 2019
Downloads Resources over HTTP in iedriver
High
CVE-2016-10562
was published
for
iedriver
(npm)
Feb 18, 2019
Downloads Resources over HTTP in node-thulac
High
CVE-2016-10640
was published
for
node-thulac
(npm)
Feb 18, 2019
Missing Origin Validation in webpack-dev-server
High
CVE-2018-14732
was published
for
webpack-dev-server
(npm)
Jan 4, 2019
Downloads Resources over HTTP in haxe-dev
High
CVE-2016-10637
was published
for
haxe-dev
(npm)
Feb 18, 2019
Downloads Resources over HTTP in grunt-ccompiler
High
CVE-2016-10636
was published
for
grunt-ccompiler
(npm)
Feb 18, 2019
High severity vulnerability that affects gun
High
GHSA-886v-mm6p-4m66
was published
for
gun
(npm)
Jun 5, 2019
SQL Injection in waterline-sequel
High
CVE-2016-10551
was published
for
waterline-sequel
(npm)
Feb 18, 2019
Electron protocol handler browser vulnerable to Command Injection
High
CVE-2018-1000118
was published
for
electron
(npm)
Mar 26, 2018
ProTip!
Advisories are also available from the
GraphQL API