GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,978
Erlang
29
GitHub Actions
16
Go
1,768
Maven
4,991
npm
3,537
NuGet
616
pip
3,107
Pub
10
RubyGems
837
Rust
786
Swift
34
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
Prototype Pollution in json-pointer
Moderate
CVE-2021-23820
was published
for
json-pointer
(npm)
Nov 8, 2021
Prototype Pollution in json-ptr
Moderate
CVE-2021-23509
was published
for
json-ptr
(npm)
Nov 8, 2021
Prototype Pollution in node-jsonpointer
Moderate
CVE-2021-23807
was published
for
jsonpointer
(npm)
Nov 8, 2021
Improperly Controlled Modification of Dynamically-Determined Object Attributes in express-mock-middleware
Moderate
CVE-2020-7616
was published
for
express-mock-middleware
(npm)
Dec 9, 2021
Prototype Pollution in merge-deep2.
Moderate
CVE-2021-23700
was published
for
merge-deep2
(npm)
Dec 16, 2021
Sandbox escape in notevil and argencoders-notevil
Moderate
CVE-2021-23771
was published
for
argencoders-notevil
(npm)
Mar 18, 2022
Prototype Pollution in querymen
Moderate
CVE-2022-25871
was published
for
querymen
(npm)
Jun 18, 2022
@ianwalter/merge Prototype Pollution via `merge` function
Moderate
CVE-2021-23397
was published
for
@ianwalter/merge
(npm)
Jul 26, 2022
express-xss-sanitizer vulnerable to Prototype Pollution via allowedTags attribute
Moderate
CVE-2022-21169
was published
for
express-xss-sanitizer
(npm)
Sep 27, 2022
deep-object-diff vulnerable to Prototype Pollution
Moderate
CVE-2022-41713
was published
for
deep-object-diff
(npm)
Nov 4, 2022
fastest-json-copy vulnerable to Prototype Pollution
Moderate
CVE-2022-41714
was published
for
fastest-json-copy
(npm)
Nov 4, 2022
deep-parse-json vulnerable to Prototype Pollution
Moderate
CVE-2022-42743
was published
for
deep-parse-json
(npm)
Nov 4, 2022
xml2js is vulnerable to prototype pollution
Moderate
CVE-2023-0842
was published
for
xml2js
(npm)
Apr 5, 2023
antfu/utils vulnerable to prototype pollution
Moderate
CVE-2023-2972
was published
for
@antfu/utils
(npm)
May 30, 2023
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name
Moderate
CVE-2023-26920
was published
for
fast-xml-parser
(npm)
Jun 13, 2023
tough-cookie Prototype Pollution vulnerability
Moderate
CVE-2023-26136
was published
for
tough-cookie
(npm)
Jul 1, 2023
Prototype pollution not blocked by object-path related utilities in hoolock
Moderate
CVE-2024-23339
was published
for
hoolock
(npm)
Jan 23, 2024
ProTip!
Advisories are also available from the
GraphQL API