GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
53 advisories
Filter by severity
curlrequest allows execution of arbitrary commands
Critical
CVE-2020-7646
was published
for
curlrequest
(npm)
May 13, 2020
Command injection in get-git-data
Critical
CVE-2020-7619
was published
for
get-git-data
(npm)
May 10, 2021
Integer Overflow in go-jose
High
CVE-2016-9123
was published
for
github.com/square/go-jose
(Go)
Jun 23, 2021
OS Command Injection in strong-nginx-controller
Critical
CVE-2020-7621
was published
for
strong-nginx-controller
(npm)
Feb 10, 2022
karma-mojo enables OS Command Injection
Critical
CVE-2020-7626
was published
for
karma-mojo
(npm)
Feb 10, 2022
OS Command Injection in node-key-sender
Critical
CVE-2020-7627
was published
for
node-key-sender
(npm)
Feb 10, 2022
OS Command Injection in git-add-remote
Critical
CVE-2020-7630
was published
for
git-add-remote
(npm)
Feb 10, 2022
OS Command Injection in install-package
Critical
CVE-2020-7629
was published
for
install-package
(npm)
Feb 10, 2022
Denial of service via insufficient metadata validation
Moderate
GHSA-p93v-m2r2-4387
was published
for
github.com/google/fscrypt
(Go)
Mar 1, 2022
CodeIgniter arbitrary code execution
Critical
CVE-2016-10131
was published
for
bcit-ci/codeigniter
(Composer)
May 17, 2022
Numpy Deserialization of Untrusted Data
Critical
CVE-2019-6446
was published
for
numpy
(pip)
May 24, 2022
Squalor SQL Injection vulnerability
Critical
CVE-2020-36645
was published
for
github.com/square/squalor
(Go)
Jan 7, 2023
AVideo contains Command injection when embedding a video link
Critical
CVE-2023-25313
was published
for
wwbn/avideo
(Composer)
Feb 2, 2023
langchain vulnerable to arbitrary code execution
Critical
CVE-2023-36188
was published
for
langchain
(pip)
Jul 6, 2023
Kube-proxy may unintentionally forward traffic
Moderate
CVE-2021-25736
was published
for
k8s.io/kubernetes
(Go)
Oct 30, 2023
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)
High
CVE-2024-22196
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 11, 2024
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
High
CVE-2024-22197
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 11, 2024
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
High
CVE-2024-22198
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 11, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature
Critical
CVE-2024-23827
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 29, 2024
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF
High
CVE-2024-23828
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 29, 2024
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
Critical
CVE-2024-2952
was published
for
litellm
(pip)
Apr 10, 2024
1Panel arbitrary file write vulnerability
Moderate
CVE-2024-34352
was published
for
github.com/1Panel-dev/1Panel
(Go)
May 9, 2024
ProTip!
Advisories are also available from the
GraphQL API