GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            300,097 advisories
        Filter by severity
        
      
      
    
                    
                      rest-client allows local users to obtain sensitive information by reading the log
                    
                      
  Low
                    
                
                      
                        CVE-2015-3448
                      
                      was published
                        for
                        
                          rest-client
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      paperclip Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-2963
                      
                      was published
                        for
                        
                          paperclip
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rails-html-sanitizer Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7578
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record subject to strong parameters protection bypass
                    
                      
  High
                    
                
                      
                        CVE-2014-3514
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects validator
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7453
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects validator
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7451
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Arbitrary JavaScript Execution in bassmaster
                    
                      
  Critical
                    
                
                      
                        CVE-2014-7205
                      
                      was published
                        for
                        
                          bassmaster
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects validator
                    
                      
  Moderate
                    
                
                      
                        GHSA-9959-c6q6-6qp3
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Oct 24, 2017 
                        •
                        
                          withdrawn
                    
                  
                    
                      facter, hiera, mcollective-client, and puppet affected by untrusted search path vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-3248
                      
                      was published
                        for
                        
                          facter
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rails-html-sanitizer Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7579
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects validator
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7452
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-0082
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Moderate severity vulnerability that affects handlebars
                    
                      
  Moderate
                    
                
                      
                        GHSA-fmr4-7g9q-7hc7
                      
                      was published
                        for
                        
                          handlebars
                        
                        (npm)
                      Oct 24, 2017 
                        •
                        
                          withdrawn
                    
                  
                    
                      Moderate severity vulnerability that affects ember
                    
                      
  Moderate
                    
                
                      
                        GHSA-vxp4-25qp-86qh
                      
                      was published
                        for
                        
                          ember
                        
                        (npm)
                      Oct 24, 2017 
                        •
                        
                          withdrawn
                    
                  
                    
                      Multiple XSS Filter Bypasses in validator
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-7454
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      VBScript Content Injection in marked
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-1370
                      
                      was published
                        for
                        
                          marked
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Potential for Script Injection in syntax-error
                    
                      
  High
                    
                
                      
                        CVE-2014-7192
                      
                      was published
                        for
                        
                          syntax-error
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      rails-html-sanitizer Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7580
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API