GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
155 advisories
Filter by severity
Command injection in wc-cmd
Critical
CVE-2020-28431
was published
for
wc-cmd
(npm)
Mar 19, 2021
•
withdrawn
Madge vulnerable to command injection
High
CVE-2021-23352
was published
for
madge
(npm)
Mar 12, 2021
Command injection in samba-client
Critical
CVE-2021-27185
was published
for
samba-client
(npm)
Feb 11, 2021
Command Injection in @graphql-tools/git-loader
High
CVE-2021-23326
was published
for
@graphql-tools/git-loader
(npm)
Jan 29, 2021
Command injection in ts-process-promises
Critical
CVE-2020-7784
was published
for
ts-process-promises
(npm)
Jan 13, 2021
Environment Variable Injection in GitHub Actions
Low
CVE-2020-15228
was published
for
@actions/core
(npm)
Oct 1, 2020
Command Injection in entitlements
High
GHSA-g8vp-6hv4-m67c
was published
for
entitlements
(npm)
Sep 11, 2020
Command Injection in wxchangba
Moderate
GHSA-j6v9-xgvh-f796
was published
for
wxchangba
(npm)
Sep 11, 2020
Command Injection in soletta-dev-app
High
GHSA-8mgg-5x65-m4m4
was published
for
soletta-dev-app
(npm)
Sep 11, 2020
Command Injection in traceroute
Critical
GHSA-rjvj-673q-4hfw
was published
for
traceroute
(npm)
Sep 4, 2020
Command Injection in npm-git-publish
Critical
GHSA-49mg-94fc-2fx6
was published
for
npm-git-publish
(npm)
Sep 4, 2020
Command Injection in meta-git
Critical
GHSA-qcff-ffx3-m25c
was published
for
meta-git
(npm)
Sep 4, 2020
Command Injection in plotter
Critical
GHSA-65xx-c85x-wg76
was published
for
plotter
(npm)
Sep 4, 2020
Command Injection in gnuplot
Critical
GHSA-cfwc-xjfp-44jg
was published
for
gnuplot
(npm)
Sep 4, 2020
Command Injection in local-devices
High
GHSA-w725-67p7-xv22
was published
for
local-devices
(npm)
Sep 3, 2020
pullit vulnerable to command injection
High
CVE-2018-25083
was published
for
pullit
(npm)
Sep 3, 2020
Command Injection in priest-runner
Critical
GHSA-9px9-f7jw-fwhj
was published
for
priest-runner
(npm)
Sep 3, 2020
Command Injection in expressfs
High
GHSA-mxmj-84q8-34r7
was published
for
expressfs
(npm)
Sep 3, 2020
Command Injection in node-wifi
Critical
GHSA-4x6x-782q-jfc4
was published
for
node-wifi
(npm)
Sep 3, 2020
ProTip!
Advisories are also available from the
GraphQL API