GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            74 advisories
        Filter by severity
        
      
      
    
                    
                      Path Traversal in angular-http-server
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-3713
                      
                      was published
                        for
                        
                          angular-http-server
                        
                        (npm)
                      Jul 26, 2018 
                    
                  
                    
                      Remote Code Execution in markdown-pdf
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-3770
                      
                      was published
                        for
                        
                          markdown-pdf
                        
                        (npm)
                      Jul 27, 2018 
                    
                  
                    
                      Arbitrary File Write via Archive Extraction in unzipper
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-1002203
                      
                      was published
                        for
                        
                          unzipper
                        
                        (npm)
                      Jul 27, 2018 
                    
                  
                    
                      Arbitrary File Write in adm-zip
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-1002204
                      
                      was published
                        for
                        
                          adm-zip
                        
                        (npm)
                      Jul 27, 2018 
                    
                  
                    
                      Directory Traversal in easyquick
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-16109
                      
                      was published
                        for
                        
                          easyquick
                        
                        (npm)
                      Aug 29, 2018 
                    
                  
                    
                      Directory Traversal in augustine
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-0930
                      
                      was published
                        for
                        
                          augustine
                        
                        (npm)
                      Sep 18, 2018 
                    
                  
                    
                      Path Traversal in simplehttpserver
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-16478
                      
                      was published
                        for
                        
                          simplehttpserver
                        
                        (npm)
                      Dec 6, 2018 
                    
                  
                    
                      Directory Traversal in restafary
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-10528
                      
                      was published
                        for
                        
                          restafary
                        
                        (npm)
                      Feb 18, 2019 
                    
                  
                    
                      m-server Vulnerable to Directory Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-16485
                      
                      was published
                        for
                        
                          m-server
                        
                        (npm)
                      Feb 18, 2019 
                    
                  
                    
                      Path Traversal in statics-server
                    
                      
  Moderate
                    
                
                      
                        GHSA-74cp-qw7f-7hpw
                      
                      was published
                        for
                        
                          statics-server
                        
                        (npm)
                      Jun 5, 2019 
                    
                  
                    
                      Path Traversal in m-server
                    
                      
  Moderate
                    
                
                      
                        GHSA-vc6r-4x6g-mmqc
                      
                      was published
                        for
                        
                          m-server
                        
                        (npm)
                      Jun 11, 2019 
                    
                  
                    
                      Path Traversal in http-file-server
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-5447
                      
                      was published
                        for
                        
                          http-file-server
                        
                        (npm)
                      Jul 16, 2019 
                    
                  
                    
                      Path Traversal in statichttpserver
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-5480
                      
                      was published
                        for
                        
                          statichttpserver
                        
                        (npm)
                      Sep 4, 2019 
                    
                  
                    
                      Path Traversal in statics-server
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-15596
                      
                      was published
                        for
                        
                          statics-server
                        
                        (npm)
                      Mar 31, 2020 
                    
                  
                    
                      Arbitrary File Read in Snyk Broker
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-7651
                      
                      was published
                        for
                        
                          snyk-broker
                        
                        (npm)
                      Jun 3, 2020 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API