GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,347
Maven
5,000+
npm
3,976
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,940 advisories
Filter by severity
Improper Input Validation in Apache Airflow resulting in Remote Code Execution
High
CVE-2017-15720
was published
for
apache-airflow
(pip)
Jan 25, 2019
Improper Input Validation in Apache Qpid Broker-J
High
CVE-2019-0200
was published
for
org.apache.qpid:apache-qpid-broker-j
(Maven)
Mar 7, 2019
Improper Input Validation python-gnupg
High
CVE-2019-6690
was published
for
python-gnupg
(pip)
Mar 25, 2019
Improper Input Validation in python-dbusmock
High
CVE-2015-1326
was published
for
python-dbusmock
(pip)
Apr 23, 2019
Improper Input Validation in Google TensorFlow
High
CVE-2018-7577
was published
for
tensorflow
(pip)
Apr 30, 2019
Improper Input Validation in Apache Sanselan
High
CVE-2018-17201
was published
for
org.apache.sanselan:sanselan
(Maven)
May 14, 2019
assign-deep Vulnerable to Prototype Pollution
High
CVE-2019-10745
was published
for
assign-deep
(npm)
Aug 21, 2019
Improper Input Validation and Cross-Site Request Forgery in Keycloak
High
CVE-2019-10199
was published
for
org.keycloak:keycloak-core
(Maven)
Sep 23, 2019
Regular Expression Denial of Service in csv-parse
High
CVE-2019-17592
was published
for
csv-parse
(npm)
Oct 15, 2019
Argument injection in a MimeTypeGuesser in Symfony
High
CVE-2019-18888
was published
for
symfony/http-foundation
(Composer)
Dec 2, 2019
Improper input validation in Apache Olingo
High
CVE-2019-17555
was published
for
org.apache.olingo:odata-client-core
(Maven)
Feb 4, 2020
Improper Input Validation in Apache Solr
High
CVE-2019-17558
was published
for
org.apache.solr:solr-core
(Maven)
Feb 12, 2020
TaffyDB can allow access to any data items in the DB
High
CVE-2019-10790
was published
for
taffy
(npm)
Feb 19, 2020
Remote Code Execution - JavaEL Injection (low privileged accounts) in Nexus Repository Manager
High
CVE-2020-10204
was published
for
org.sonatype.nexus:nexus-core
(Maven)
Apr 14, 2020
Prototype Pollution Protection Bypass in qs
High
CVE-2017-1000048
was published
for
qs
(npm)
Apr 30, 2020
Arbitrary code execution in Apache Commons BeanUtils
High
CVE-2014-0114
was published
for
commons-beanutils:commons-beanutils
(Maven)
Jun 10, 2020
Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names
High
CVE-2020-8184
was published
for
rack
(RubyGems)
Jun 24, 2020
Information Exposure in Netty
High
CVE-2015-2156
was published
for
io.netty:netty
(Maven)
Jun 30, 2020
Denial of service in XStream
High
CVE-2017-7957
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jun 30, 2020
Improper Input Validation in sails-hook-sockets
High
CVE-2018-21036
was published
for
sails-hook-sockets
(npm)
Jul 24, 2020
ProTip!
Advisories are also available from the
GraphQL API