GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            300,097 advisories
        Filter by severity
        
      
      
    
                    
                      Local API Login Credentials Disclosure in paratrooper-pingdom
                    
                      
  Low
                    
                
                      
                        CVE-2014-1233
                      
                      was published
                        for
                        
                          paratrooper-pingdom
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Path Traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2014-0130
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      sprockets vulnerable to Path Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-7819
                      
                      was published
                        for
                        
                          sprockets
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      sfpagent Command Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2014-2888
                      
                      was published
                        for
                        
                          sfpagent
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rack-ssl Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-2538
                      
                      was published
                        for
                        
                          rack-ssl
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack allows bypass of database-query restrictions
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6417
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record contains SQL Injection via improper range quoting
                    
                      
  High
                    
                
                      
                        CVE-2014-3483
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record Improper Access Control
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7577
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Exposure of Sensitive Information in bio-basespace-sdk
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7111
                      
                      was published
                        for
                        
                          bio-basespace-sdk
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      File Descriptor Leak Can Cause DoS Vulnerability in hapi
                    
                      
  High
                    
                
                      
                        CVE-2014-3742
                      
                      was published
                        for
                        
                          hapi
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in uglify-js
                    
                      
  High
                    
                
                      
                        CVE-2015-8858
                      
                      was published
                        for
                        
                          uglify-js
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Aescrypt does not sufficiently use random values
                    
                      
  High
                    
                
                      
                        CVE-2013-7463
                      
                      was published
                        for
                        
                          aescrypt
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack is vulnerable to denial of service because of a wildcard controller route
                    
                      
  High
                    
                
                      
                        CVE-2015-7581
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      jquery-rails and jquery-ujs subject to Exposure of Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-1840
                      
                      was published
                        for
                        
                          jquery-rails
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack vulnerable to Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6415
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Paratrooper-newrelic Exposes of Sensitive Information to an Unauthorized Actor
                    
                      
  Low
                    
                
                      
                        CVE-2014-1234
                      
                      was published
                        for
                        
                          paratrooper-newrelic
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack vulnerable to Path Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-7818
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack is vulnerable to remote bypass authentication
                    
                      
  Low
                    
                
                      
                        CVE-2015-7576
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      activesupport Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3226
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rest-client allows local users to obtain sensitive information by reading the log
                    
                      
  Low
                    
                
                      
                        CVE-2015-3448
                      
                      was published
                        for
                        
                          rest-client
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      paperclip Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-2963
                      
                      was published
                        for
                        
                          paperclip
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rails-html-sanitizer Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7578
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      will_paginate Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6459
                      
                      was published
                        for
                        
                          will_paginate
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record subject to strong parameters protection bypass
                    
                      
  High
                    
                
                      
                        CVE-2014-3514
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Denial-of-Service Memory Exhaustion in qs
                    
                      
  High
                    
                
                      
                        CVE-2014-7191
                      
                      was published
                        for
                        
                          qs
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API