GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,549 advisories
Filter by severity
Content injection in marked
Moderate
GHSA-wjmf-58vc-xqjr
was published
for
marked
(npm)
Feb 25, 2021
•
withdrawn
Regular Expression Denial of Service
Moderate
GHSA-7m7q-q53v-j47v
was published
for
marked
(npm)
Feb 25, 2021
•
withdrawn
Cross-Site Scripting in marked
Moderate
GHSA-8wp3-cp9v-44fm
was published
for
marked
(npm)
Feb 25, 2021
•
withdrawn
Regular Expression Denial of Service
Moderate
GHSA-jcgq-xh2f-2hfm
was published
for
eslint
(npm)
Feb 25, 2021
•
withdrawn
HTML tag injection
Moderate
GHSA-9vhv-p9r7-rm53
was published
for
serve-handler
(npm)
Feb 23, 2021
•
withdrawn
Incorrect Authorization
Moderate
GHSA-5hx7-77g4-wqx3
was published
for
aedes
(npm)
Feb 23, 2021
•
withdrawn
Regular Expression Denial of Service (REDoS) in Marked
Moderate
CVE-2021-21306
was published
for
marked
(npm)
Feb 8, 2021
CKEditor 5 Markdown plugin Regular expression Denial of Service
Moderate
CVE-2021-21254
was published
for
@ckeditor/ckeditor5-markdown-gfm
(npm)
Jan 29, 2021
IPC messages delivered to the wrong frame in Electron
Moderate
CVE-2020-26272
was published
for
electron
(npm)
Jan 28, 2021
CORS misconfiguration in socket.io
Moderate
CVE-2020-28481
was published
for
socket.io
(npm)
Jan 20, 2021
Cross-site scripting vulnerability in TinyMCE
Moderate
CVE-2024-21911
was published
for
TinyMCE
(Composer)
Jan 6, 2021
Axios vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-28168
was published
for
axios
(npm)
Jan 4, 2021
Hostname spoofing via backslashes in URL
Moderate
CVE-2020-26291
was published
for
urijs
(npm)
Dec 30, 2020
OS Command Injection in node-notifier
Moderate
CVE-2020-7789
was published
for
node-notifier
(npm)
Dec 21, 2020
Cross-site Scripting in dompurify
Moderate
CVE-2020-26870
was published
for
dompurify
(npm)
Dec 18, 2020
Command Injection Vulnerability in systeminformation
Moderate
CVE-2020-26274
was published
for
systeminformation
(npm)
Dec 16, 2020
ReDOS vulnerabities: multiple grammars
Moderate
GHSA-7wwv-vh3v-89cq
was published
for
@highlightjs/cdn-assets
(npm)
Dec 4, 2020
Prototype Pollution in systeminformation
Moderate
CVE-2020-26245
was published
for
systeminformation
(npm)
Nov 27, 2020
ProTip!
Advisories are also available from the
GraphQL API