GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
6,194 advisories
Filter by severity
Arbitrary File Read in phantom-html-to-pdf
High
CVE-2020-7763
was published
for
phantom-html-to-pdf
(npm)
Nov 6, 2020
Directory Traversal vulnerability in GET/PUT allows attackers to Disclose Information or Write Files via a crafted GET/PUT request
Low
CVE-2020-15239
was published
for
xmpp-http-upload
(pip)
Oct 6, 2020
Arbitrary File Write in iobroker.admin
Critical
CVE-2019-10765
was published
for
iobroker.admin
(npm)
Sep 4, 2020
Path Traversal in @wturyn/swagger-injector
Critical
GHSA-4x7w-frcq-v4m3
was published
for
@wturyn/swagger-injector
(npm)
Sep 3, 2020
Path Traversal in swagger-injector
Critical
GHSA-v4x8-gw49-7hv4
was published
for
swagger-injector
(npm)
Sep 3, 2020
Path Traversal in restify-swagger-jsdoc
High
GHSA-gvff-25cc-4f66
was published
for
restify-swagger-jsdoc
(npm)
Sep 3, 2020
Path Traversal in file-static-server
High
GHSA-qjfh-xc44-rm9x
was published
for
file-static-server
(npm)
Sep 3, 2020
Path Traversal in express-cart
High
GHSA-8h8v-6qqm-fwpq
was published
for
express-cart
(npm)
Sep 1, 2020
Directory Traversal in @vivaxy/here
High
GHSA-m4vv-p6fq-jhqp
was published
for
@vivaxy/here
(npm)
Sep 1, 2020
Directory Traversal in featurebook
Moderate
GHSA-7x92-2j68-h32c
was published
for
featurebook
(npm)
Sep 1, 2020
Directory Traversal in section2.madisonjbrooks12
High
CVE-2017-16172
was published
for
section2.madisonjbrooks12
(npm)
Sep 1, 2020
Directory Traversal in jansenstuffpleasework
High
CVE-2017-16176
was published
for
jansenstuffpleasework
(npm)
Sep 1, 2020
Directory Traversal in chatbyvista
High
CVE-2017-16177
was published
for
chatbyvista
(npm)
Sep 1, 2020
Directory Traversal in wintiwebdev
High
CVE-2017-16181
was published
for
wintiwebdev
(npm)
Sep 1, 2020
ProTip!
Advisories are also available from the
GraphQL API