GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
ecdsa-elixir fails to check signatures, vulnerable to message forging
Critical
CVE-2021-43568
was published
for
ecdsa-elixir
(Erlang)
May 24, 2022
Phoenix Arbitrary URL Redirect
Moderate
CVE-2017-1000163
was published
for
phoenix
(Erlang)
Apr 12, 2022
phoenix_html allows Cross-site Scripting in HEEx class attributes
Moderate
CVE-2021-46871
was published
for
phoenix_html
(Erlang)
Jan 10, 2023
Cross-site Scripting in RabbitMQ
Low
CVE-2019-11291
was published
for
rabbit_common
(Erlang)
May 24, 2022
alchemist.vim vulnerable to remote code execution
Critical
CVE-2017-1000212
was published
for
alchemist.vim
(Erlang)
May 13, 2022
Remote Code Execution in paginator
Critical
CVE-2020-15150
was published
for
paginator
(Erlang)
Apr 12, 2022
Null Byte Injection in Plug.Static
High
CVE-2017-1000052
was published
for
plug
(Erlang)
Apr 12, 2022
XSS in HEEx class attributes
Moderate
GHSA-j3gg-r6gp-95q2
was published
for
phoenix_html
(Erlang)
Apr 12, 2022
Inline DTD allows XML bomb attack
High
CVE-2019-15160
was published
for
sweet_xml
(Erlang)
Apr 12, 2022
Arbitrary Code Execution in Cookie Serialization
High
CVE-2017-1000053
was published
for
plug
(Erlang)
Apr 12, 2022
Permissive parameters and privilege escalation
Moderate
CVE-2018-20301
was published
for
coherence
(Erlang)
Feb 10, 2022
ProTip!
Advisories are also available from the
GraphQL API