GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
45 advisories
Filter by severity
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The...
Critical
Unreviewed
CVE-2024-12641
was published
Dec 16, 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
Critical
CVE-2024-48914
was published
for
@vendure/asset-server-plugin
(npm)
Oct 15, 2024
Escalation of privileges in @sap/xssec
Critical
CVE-2023-49583
was published
for
@sap/xssec
(npm)
Dec 12, 2023
Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In...
Critical
Unreviewed
CVE-2023-39332
was published
Oct 18, 2023
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the...
Critical
Unreviewed
CVE-2023-32002
was published
Aug 21, 2023
SES's dynamic import and spread operator provides possible path to arbitrary exfiltration and execution
Critical
CVE-2023-39532
was published
for
ses
(npm)
Aug 9, 2023
SwiftNIO vulnerable to HTTP request smuggling using malformed Transfer-Encoding header
Critical
GHSA-mgc4-wqv7-4pxm
was published
for
github.com/apple/swift-nio
(Swift)
May 18, 2023
angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend
Critical
CVE-2023-28444
was published
for
angular-server-side-configuration
(npm)
Mar 24, 2023
builderio/qwik is vulnerable to code injection
Critical
CVE-2023-1283
was published
for
@builder.io/qwik
(npm)
Mar 9, 2023
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with...
Critical
Unreviewed
CVE-2022-35255
was published
Dec 6, 2022
fs2-io skips mTLS client verification
Critical
CVE-2022-31183
was published
for
co.fs2:fs2-io
(Maven)
Jul 29, 2022
llhttp allows HTTP Request Smuggling via Flawed Parsing of Transfer-Encoding
Critical
CVE-2022-32213
was published
for
llhttp
(npm)
Jul 15, 2022
llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields
Critical
CVE-2022-32214
was published
for
llhttp
(npm)
Jul 15, 2022
Improper Neutralization of Special Elements used in a Command in Shell-quote
Critical
CVE-2021-42740
was published
for
shell-quote
(npm)
May 24, 2022
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS,...
Critical
Unreviewed
CVE-2021-22931
was published
May 24, 2022
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug...
Critical
Unreviewed
CVE-2020-8265
was published
May 24, 2022
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js...
Critical
Unreviewed
CVE-2020-8252
was published
May 24, 2022
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver...
Critical
Unreviewed
CVE-2020-8201
was published
May 24, 2022
Node-Traceroute RCE Vulnerability
Critical
CVE-2018-21268
was published
for
traceroute
(npm)
May 24, 2022
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read()...
Critical
Unreviewed
CVE-2017-15896
was published
May 13, 2022
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary...
Critical
Unreviewed
CVE-2016-3987
was published
May 13, 2022
ejs template injection vulnerability
Critical
CVE-2022-29078
was published
for
ejs
(npm)
Apr 26, 2022
Command injection in npm-dependency-versions
Critical
CVE-2022-29080
was published
for
npm-dependency-versions
(npm)
Apr 13, 2022
ProTip!
Advisories are also available from the
GraphQL API