GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
210 advisories
Filter by severity
mpregular is a package that provides a small program development framework based on RegularJS. A...
High
Unreviewed
CVE-2025-57323
was published
Sep 24, 2025
messageformat prototype pollution vulnerability
High
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
Vulnerability of exposing object heap addresses in the Ark eTS module.
Impact: Successful...
High
Unreviewed
CVE-2025-58280
was published
Sep 5, 2025
devalue prototype pollution vulnerability
High
CVE-2025-57820
was published
for
devalue
(npm)
Aug 26, 2025
Prototype Pollution in jquery-deparam
High
CVE-2021-20087
was published
for
jquery-deparam
(npm)
May 24, 2021
content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE
High
CVE-2025-55164
was published
for
content-security-policy-parser
(npm)
Aug 12, 2025
js-toml Prototype Pollution Vulnerability
High
CVE-2025-54803
was published
for
js-toml
(npm)
Aug 4, 2025
@stryker-mutator/util vulnerable to Prototype Pollution
High
CVE-2024-57085
was published
for
@stryker-mutator/util
(npm)
Feb 6, 2025
@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
High
CVE-2025-34146
was published
for
@nyariv/sandboxjs
(npm)
Jul 31, 2025
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
High
CVE-2025-8101
was published
for
linkifyjs
(npm)
Jul 26, 2025
Synchrony deobfuscator prototype pollution vulnerability leading to arbitrary code execution
High
CVE-2023-45811
was published
for
deobfuscator
(npm)
Oct 18, 2023
Duplicate Advisory: Prototype Pollution in min-dash
High
GHSA-fm93-fhh2-cg2c
was published
for
min-dash
(npm)
Jan 27, 2022
•
withdrawn
Duplicate Advisory: Prototype Pollution in klona
High
GHSA-4r97-78gf-q24v
was published
for
klona
(npm)
Sep 4, 2020
•
withdrawn
hoek subject to prototype pollution via the clone function.
High
CVE-2020-36604
was published
for
@hapi/hoek
(npm)
Sep 25, 2022
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype...
High
Unreviewed
CVE-2022-1802
was published
Dec 22, 2022
An attacker could have sent a message to the parent process where the contents were used to...
High
Unreviewed
CVE-2022-1529
was published
Dec 22, 2022
If an object prototype was corrupted by an attacker, they would have been able to set undesired...
High
Unreviewed
CVE-2022-2200
was published
Dec 22, 2022
js-object-utilities Vulnerable to Prototype Pollution
High
CVE-2025-28269
was published
for
js-object-utilities
(npm)
Apr 7, 2025
node-opcua-alarm-condition prototype pollution vulnerability
High
CVE-2024-57086
was published
for
node-opcua-alarm-condition
(npm)
Feb 6, 2025
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined...
High
Unreviewed
CVE-2024-12556
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API