GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            300,097 advisories
        Filter by severity
        
      
      
    
                    
                      Web Console (Ruby gem) contains whitelisted_ips bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3224
                      
                      was published
                        for
                        
                          web-console
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rbovirt uses the rest-client gem with SSL verification disabled
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-0036
                      
                      was published
                        for
                        
                          rbovirt
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Rack vulnerable to Denial of Service via large parameter depth request
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3225
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      dns-sync command injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2014-9682
                      
                      was published
                        for
                        
                          dns-sync
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Mail Gem CRLF Injection vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-9097
                      
                      was published
                        for
                        
                          mail
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6416
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Arabic Prawn allows remote attackers to execute arbitrary commands via shell metacharacters
                    
                      
  High
                    
                
                      
                        CVE-2014-2322
                      
                      was published
                        for
                        
                          arabic-prawn
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      sprout Arbitrary Code Execution vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2013-6421
                      
                      was published
                        for
                        
                          sprout
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Webbynode Code Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2013-7086
                      
                      was published
                        for
                        
                          webbynode
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in marked
                    
                      
  High
                    
                
                      
                        CVE-2015-8854
                      
                      was published
                        for
                        
                          marked
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      colorscore Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2015-7541
                      
                      was published
                        for
                        
                          colorscore
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      sentry-raven allows remote attackers to cause a denial of service via a large exponent value in a scientific number
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-9490
                      
                      was published
                        for
                        
                          sentry-raven
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Cross-Site Scripting in serve-index
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-8856
                      
                      was published
                        for
                        
                          serve-index
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Creme Fraiche contains OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2013-2090
                      
                      was published
                        for
                        
                          cremefraiche
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Shell command injection in command_wrap
                    
                      
  High
                    
                
                      
                        CVE-2013-1875
                      
                      was published
                        for
                        
                          command_wrap
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionmailer email address processing causes Denial of service
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4389
                      
                      was published
                        for
                        
                          actionmailer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      i18n gem Cross-site Scripting vulnerability 
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4492
                      
                      was published
                        for
                        
                          i18n
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Code injection in dragonfly gem
                    
                      
  High
                    
                
                      
                        CVE-2013-5671
                      
                      was published
                        for
                        
                          dragonfly
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Dragonfly Code Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2013-1756
                      
                      was published
                        for
                        
                          dragonfly
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      jquery-ui Tooltip widget vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-6662
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1855
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      activesupport in Rails vulnerable to incorrect data conversion
                    
                      
  High
                    
                
                      
                        CVE-2013-0333
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4761
                      
                      was published
                        for
                        
                          puppet
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6414
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API