GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,094 advisories
Filter by severity
CKEditor cross-site scripting vulnerability in AJAX sample
Moderate
CVE-2023-4771
was published
for
ckeditor4
(npm)
Feb 7, 2024
CKEditor4 Cross-site Scripting vulnerability in samples with enabled the preview feature
Moderate
CVE-2024-24816
was published
for
ckeditor4
(npm)
Feb 7, 2024
CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection
Moderate
CVE-2024-24815
was published
for
ckeditor/ckeditor
(Composer)
Feb 7, 2024
Stimulsoft Dashboard.JS Cross Site Scripting vulnerability
Moderate
CVE-2024-24396
was published
for
stimulsoft-dashboards-js
(npm)
Feb 5, 2024
Stimulsoft Dashboard.JS Cross Site Scripting vulnerability
Moderate
CVE-2024-24397
was published
for
stimulsoft-dashboards-js
(npm)
Feb 5, 2024
Zmarkdown Server-Side Request Forgery (SSRF) in remark-download-images
Moderate
GHSA-mf74-qq7w-6j7v
was published
for
remark-images-download
(npm)
Feb 3, 2024
Dash apps vulnerable to Cross-site Scripting
Moderate
CVE-2024-21485
was published
for
dash
(npm)
Feb 2, 2024
nodemailer ReDoS when trying to send a specially crafted email
Moderate
GHSA-9h6g-pr28-7cqp
was published
for
nodemailer
(npm)
Jan 31, 2024
@lobehub/chat vulnerable to unauthorized access to plugins
Moderate
CVE-2024-24566
was published
for
@lobehub/chat
(npm)
Jan 31, 2024
Prototype pollution not blocked by object-path related utilities in hoolock
Moderate
CVE-2024-23339
was published
for
hoolock
(npm)
Jan 23, 2024
@hono/node-server cannot handle "double dots" in URL
Moderate
CVE-2024-23340
was published
for
@hono/node-server
(npm)
Jan 23, 2024
Default swagger-ui configuration exposes all files in the module
Moderate
CVE-2024-22207
was published
for
@fastify/swagger-ui
(npm)
Jan 16, 2024
react-native-mmkv Insertion of Sensitive Information into Log File vulnerability
Moderate
CVE-2024-21668
was published
for
react-native-mmkv
(npm)
Jan 9, 2024
Apprite CLI makes Use of Hard-coded Credentials
Moderate
CVE-2023-50974
was published
for
appwrite
(npm)
Jan 9, 2024
@fastify/reply-from JSON Content-Type parsing confusion
Moderate
CVE-2023-51701
was published
for
@fastify/reply-from
(npm)
Jan 8, 2024
Arbitrary remote file read in Wrangler dev server
Moderate
CVE-2023-7079
was published
for
wrangler
(npm)
Jan 3, 2024
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE
Moderate
GHSA-gjhc-6xm7-mc8q
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE plugins
Moderate
GHSA-wxj2-777f-vxmf
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE
Moderate
GHSA-q5pp-5q2h-g8rv
was published
for
tinymce
(npm)
Jan 3, 2024
•
withdrawn
Follow Redirects improperly handles URLs in the url.parse() function
Moderate
CVE-2023-26159
was published
for
follow-redirects
(npm)
Jan 2, 2024
Layui cross-site scripting (XSS) vulnerability
Moderate
CVE-2023-50550
was published
for
layui
(npm)
Dec 30, 2023
blinksocks has weak encryption algorithms
Moderate
CVE-2023-50481
was published
for
blinksocks
(npm)
Dec 21, 2023
Named path parameters can be overridden in TrieRouter
Moderate
CVE-2023-50710
was published
for
hono
(npm)
Dec 15, 2023
ProTip!
Advisories are also available from the
GraphQL API