GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
425 advisories
Filter by severity
Radiant CMS vulnerable to Cross-site Scripting
Moderate
CVE-2018-5216
was published
for
radiant
(RubyGems)
Jan 6, 2018
Cross-Site Scripting (XSS) in jquery
Moderate
CVE-2015-9251
was published
for
jQuery
(RubyGems)
Jan 22, 2018
Gyazo allows local users to write arbitrary files
Moderate
CVE-2014-4994
was published
for
gyazo
(RubyGems)
Jan 22, 2018
Sinatra Path Traversal vulnerability
Moderate
CVE-2018-7212
was published
for
sinatra
(RubyGems)
Feb 20, 2018
Ox gem stack overflow in sax_parse
Moderate
CVE-2017-16229
was published
for
ox
(RubyGems)
Mar 5, 2018
delayed_job_web Cross-site Scripting vulnerability
Moderate
CVE-2017-12097
was published
for
delayed_job_web
(RubyGems)
Mar 5, 2018
rails_admin ruby gem XSS
Moderate
CVE-2017-12098
was published
for
rails_admin
(RubyGems)
Mar 5, 2018
rack-protection gem timing attack vulnerability when validating CSRF token
Moderate
CVE-2018-1000119
was published
for
rack-protection
(RubyGems)
Mar 7, 2018
http vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2015-1828
was published
for
http
(RubyGems)
Mar 13, 2018
Doorkeeper is vulnerable to stored XSS and code execution
Moderate
CVE-2018-1000088
was published
for
doorkeeper
(RubyGems)
Mar 13, 2018
Cross-site Scripting in loofah
Moderate
CVE-2018-8048
was published
for
loofah
(RubyGems)
Mar 21, 2018
Uncontrolled resource consumption in nokogiri
Moderate
CVE-2017-18258
was published
for
nokogiri
(RubyGems)
Apr 13, 2018
rails-html-sanitizer Cross-site Scripting vulnerability
Moderate
CVE-2018-3741
was published
for
rails-html-sanitizer
(RubyGems)
Apr 26, 2018
Sinatra Cross-site Scripting vulnerability
Moderate
CVE-2018-11627
was published
for
sinatra
(RubyGems)
Jun 5, 2018
Ciborg gem for Ruby allows local users to write files and gain privileges via Symlink
Moderate
CVE-2014-5003
was published
for
ciborg
(RubyGems)
Jul 23, 2018
radiant vulnerable to Cross-site Scripting
Moderate
CVE-2018-7261
was published
for
radiant
(RubyGems)
Jul 27, 2018
Json-jwt did not verify the cryptographic signature for data
Moderate
CVE-2018-1000539
was published
for
json-jwt
(RubyGems)
Jul 31, 2018
Moderate severity vulnerability that affects safemode
Moderate
GHSA-44vc-fpcg-5cc5
was published
for
safemode
(RubyGems)
Aug 8, 2018
•
withdrawn
Nokogiri vulnerable to libxml XML Entity Expansion
Moderate
CVE-2015-1819
was published
for
nokogiri
(RubyGems)
Aug 8, 2018
grape subject to Cross-site Scripting
Moderate
CVE-2018-3769
was published
for
grape
(RubyGems)
Aug 13, 2018
Moderate severity vulnerability that affects rack-mini-profiler
Moderate
GHSA-995j-587r-259w
was published
for
rack-mini-profiler
(RubyGems)
Aug 13, 2018
•
withdrawn
Moderate severity vulnerability that affects paperclip
Moderate
GHSA-phmw-pv3f-vvx7
was published
for
paperclip
(RubyGems)
Aug 13, 2018
•
withdrawn
Moderate severity vulnerability that affects web-console
Moderate
GHSA-82x2-g7vr-39wq
was published
for
web-console
(RubyGems)
Aug 13, 2018
•
withdrawn
Moderate severity vulnerability that affects actionview
Moderate
GHSA-2pwf-xwr3-hp55
was published
for
actionview
(RubyGems)
Aug 13, 2018
•
withdrawn
Moderate severity vulnerability that affects activerecord
Moderate
GHSA-m8h6-m9p5-p2f8
was published
for
activerecord
(RubyGems)
Aug 13, 2018
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API