GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
167 advisories
Filter by severity
Prototype Pollution in deepmerge-ts
High
CVE-2022-24802
was published
for
deepmerge-ts
(npm)
Apr 1, 2022
Due to the formatting logic of the "console.table()" function it was not safe to allow user...
High
Unreviewed
CVE-2022-21824
was published
Feb 25, 2022
Prototype Pollution in safetydance
High
CVE-2020-7737
was published
for
safetydance
(npm)
Feb 10, 2022
Validation bypass in frourio-express
High
CVE-2022-23624
was published
for
frourio-express
(npm)
Feb 7, 2022
Prototype Pollution in object-path-set
High
CVE-2021-23507
was published
for
object-path-set
(npm)
Feb 5, 2022
Prototype Pollution in putil-merge
High
CVE-2021-23470
was published
for
putil-merge
(npm)
Feb 5, 2022
Prototype Pollution in @strikeentco/set
High
CVE-2021-23497
was published
for
@strikeentco/set
(npm)
Feb 5, 2022
Prototype pollution in min-dash < 3.8.1
High
GHSA-2m53-83f3-562j
was published
for
min-dash
(npm)
Feb 1, 2022
Prototype Pollution in cached-path-relative
High
CVE-2021-23518
was published
for
cached-path-relative
(npm)
Jan 27, 2022
Prototype Pollution in copy-props
High
CVE-2020-28503
was published
for
copy-props
(npm)
Jan 6, 2022
Prototype Pollution in @fabiocaccamo/utils.js
High
CVE-2021-3815
was published
for
@fabiocaccamo/utils.js
(npm)
Dec 10, 2021
Uncontrolled Resource Consumption in fun-map
High
CVE-2020-7644
was published
for
fun-map
(npm)
Dec 10, 2021
Prototype pollution in supermixer
High
CVE-2020-24939
was published
for
supermixer
(npm)
Dec 10, 2021
Prototype Pollution in record-like-deep-assign
High
CVE-2021-23402
was published
for
record-like-deep-assign
(npm)
Dec 10, 2021
Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
High
CVE-2020-28472
was published
for
@aws-sdk/shared-ini-file-loader
(npm)
Nov 16, 2021
ProTip!
Advisories are also available from the
GraphQL API