GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            113,453 advisories
        Filter by severity
        
      
      
    
                    
                      ActiveRecord in Ruby on Rails allows database-query bypass
                    
                      
  High
                    
                
                      
                        CVE-2016-6317
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack allows remote code execution via application's unrestricted use of render method
                    
                      
  High
                    
                
                      
                        CVE-2016-2098
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Directory traversal vulnerability in Action View in Ruby on Rails
                    
                      
  High
                    
                
                      
                        CVE-2016-0752
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack is vulnerable to denial of service via a crafted HTTP Accept header
                    
                      
  High
                    
                
                      
                        CVE-2016-0751
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      High severity vulnerability that affects electron
                    
                      
  High
                    
                
                      
                        CVE-2016-1202
                      
                      was published
                        for
                        
                          electron
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in is-my-json-valid
                    
                      
  High
                    
                
                      
                        CVE-2016-2537
                      
                      was published
                        for
                        
                          is-my-json-valid
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method
                    
                      
  High
                    
                
                      
                        CVE-2016-3693
                      
                      was published
                        for
                        
                          safemode
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      archive-tar-minitar and minitar vulnerable to Path Traversal
                    
                      
  High
                    
                
                      
                        CVE-2016-10173
                      
                      was published
                        for
                        
                          archive-tar-minitar
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      OpenSSL gem for Ruby using inadequate encryption strength
                    
                      
  High
                    
                
                      
                        CVE-2016-7798
                      
                      was published
                        for
                        
                          openssl
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      SQL Injection in Active Record
                    
                      
  High
                    
                
                      
                        CVE-2014-3482
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      sfpagent Command Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2014-2888
                      
                      was published
                        for
                        
                          sfpagent
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Path Traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2014-0130
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Aescrypt does not sufficiently use random values
                    
                      
  High
                    
                
                      
                        CVE-2013-7463
                      
                      was published
                        for
                        
                          aescrypt
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record contains SQL Injection via improper range quoting
                    
                      
  High
                    
                
                      
                        CVE-2014-3483
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in ms
                    
                      
  High
                    
                
                      
                        CVE-2015-8315
                      
                      was published
                        for
                        
                          ms
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      File Descriptor Leak Can Cause DoS Vulnerability in hapi
                    
                      
  High
                    
                
                      
                        CVE-2014-3742
                      
                      was published
                        for
                        
                          hapi
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in uglify-js
                    
                      
  High
                    
                
                      
                        CVE-2015-8858
                      
                      was published
                        for
                        
                          uglify-js
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Denial-of-Service Memory Exhaustion in qs
                    
                      
  High
                    
                
                      
                        CVE-2014-7191
                      
                      was published
                        for
                        
                          qs
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      Regular Expression Denial of Service in semver
                    
                      
  High
                    
                
                      
                        CVE-2015-8855
                      
                      was published
                        for
                        
                          semver
                        
                        (npm)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack is vulnerable to denial of service because of a wildcard controller route
                    
                      
  High
                    
                
                      
                        CVE-2015-7581
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record subject to strong parameters protection bypass
                    
                      
  High
                    
                
                      
                        CVE-2014-3514
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API