GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            450 advisories
        Filter by severity
        
      
      
    
                    
                      rails-html-sanitizer Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-7580
                      
                      was published
                        for
                        
                          rails-html-sanitizer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Web Console (Ruby gem) contains whitelisted_ips bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3224
                      
                      was published
                        for
                        
                          web-console
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      rbovirt uses the rest-client gem with SSL verification disabled
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-0036
                      
                      was published
                        for
                        
                          rbovirt
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Rack vulnerable to Denial of Service via large parameter depth request
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-3225
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Mail Gem CRLF Injection vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-9097
                      
                      was published
                        for
                        
                          mail
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6416
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Denial of service in ruby-openid
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1812
                      
                      was published
                        for
                        
                          ruby-openid
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      activesupport Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1856
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Spree Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1656
                      
                      was published
                        for
                        
                          spree
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      newrelic_rpm Gem Discloses Sensitive Information
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-0284
                      
                      was published
                        for
                        
                          newrelic_rpm
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      omniauth-oauth2 Cross-Site Request Forgery vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-6134
                      
                      was published
                        for
                        
                          omniauth-oauth2
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionmailer email address processing causes Denial of service
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4389
                      
                      was published
                        for
                        
                          actionmailer
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      i18n gem Cross-site Scripting vulnerability 
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4492
                      
                      was published
                        for
                        
                          i18n
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      jquery-ui Tooltip widget vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-6662
                      
                      was published
                        for
                        
                          jQuery.UI.Combined
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1855
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Puppet allows remote attackers to execute arbitrary Ruby programs from the master via the resource_type service
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4761
                      
                      was published
                        for
                        
                          puppet
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Improper Input Validation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-6414
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Active Record allows bypassing of database-query restrictions
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-0155
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      ActiveRecord vulnerable to modification of protected model attributes
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-0276
                      
                      was published
                        for
                        
                          activerecord
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      omniauth-facebook Cross-Site Request Forgery vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-4562
                      
                      was published
                        for
                        
                          omniauth-facebook
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-3463
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-1857
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      actionpack Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-3465
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      activesupport Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2012-3464
                      
                      was published
                        for
                        
                          activesupport
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API