GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
488 advisories
Filter by severity
rollbar vulnerable to Prototype Pollution in merge()
Moderate
CVE-2025-62517
was published
for
rollbar
(npm)
Oct 23, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Oct 20, 2025
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
Critical
CVE-2025-62410
was published
for
happy-dom
(npm)
Oct 15, 2025
`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
High
CVE-2025-62381
was published
for
sveltekit-superforms
(npm)
Oct 15, 2025
Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
Moderate
CVE-2025-62374
was published
for
parse
(npm)
Oct 14, 2025
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
Moderate
CVE-2025-3193
was published
for
algoliasearch-helper
(npm)
Sep 27, 2025
dref is vulnerable to prototype pollution
High
CVE-2025-26278
was published
for
dref
(npm)
Sep 25, 2025
magix-combine-ex vulnerable to prototype pollution
Low
CVE-2025-57321
was published
for
magix-combine-ex
(npm)
Sep 24, 2025
web3-core-subscriptions has a Prototype Pollution vulnerability
Low
CVE-2025-57330
was published
for
web3-core-subscriptions
(npm)
Sep 24, 2025
ts-fns has prototype pollution vulnerability
Moderate
CVE-2025-57351
was published
for
ts-fns
(npm)
Sep 24, 2025
sassdoc-extras vulnerable to prototype pollution
Low
CVE-2025-57326
was published
for
sassdoc-extras
(npm)
Sep 24, 2025
messageformat has a prototype pollution vulnerability
Low
CVE-2025-57349
was published
for
messageformat
(npm)
Sep 24, 2025
node-cube vulnerable to prototype pollution
Low
CVE-2025-57348
was published
for
node-cube
(npm)
Sep 24, 2025
mpregular vulnerable to prototype pollution
High
CVE-2025-57323
was published
for
mpregular
(npm)
Sep 24, 2025
csvjson vulnerable to prototype injection
High
CVE-2025-57318
was published
for
csvjson
(npm)
Sep 24, 2025
toggle-array vulnerable to prototype pollution
Low
CVE-2025-57328
was published
for
toggle-array
(npm)
Sep 24, 2025
A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within...
Critical
Unreviewed
CVE-2025-57347
was published
Sep 24, 2025
Duplicate Advisory: rollbar vulnerable to prototype pollution
Low
GHSA-m929-rg27-gj99
was published
for
rollbar
(npm)
Sep 24, 2025
•
withdrawn
web3-core-method is vulnerable to prototype pollution
Low
CVE-2025-57329
was published
for
web3-core-method
(npm)
Sep 24, 2025
parse is vulnerable to prototype pollution
Moderate
CVE-2025-57324
was published
for
parse
(npm)
Sep 24, 2025
spmrc vulnerable to prototype pollution
Low
CVE-2025-57327
was published
for
spmrc
(npm)
Sep 24, 2025
json-schema-editor-visual vulnerable to prototype pollution
Moderate
CVE-2025-57320
was published
for
json-schema-editor-visual
(npm)
Sep 24, 2025
fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
counterpart vulnerable to prototype pollution
Moderate
CVE-2025-57354
was published
for
counterpart
(npm)
Sep 24, 2025
CSVTOJSON has a prototype pollution vulnerability
Moderate
CVE-2025-57350
was published
for
csvtojson
(npm)
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API