Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,044 advisories

Loading
docarray prototype pollution Moderate
CVE-2025-5150 was published for docarray (pip) May 25, 2025
Remote code execution via the `pretty` option. Moderate
CVE-2021-21353 was published for pug (npm) Mar 3, 2021
OZI-Project/ozi-publish Code Injection vulnerability Moderate
CVE-2025-47271 was published for OZI-Project/publish (GitHub Actions) May 12, 2025
Froxlor vulnerable to Code Injection Moderate
CVE-2022-3721 was published for froxlor/froxlor (Composer) Nov 4, 2022
Flair allows arbitrary code execution Moderate
CVE-2024-10073 was published for flair (pip) Oct 17, 2024
m3t3kh4n wnowicki
Credited to m3t3kh4n and wnowicki
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. Moderate Unreviewed
CVE-2023-42404 was published Apr 28, 2025
Pug allows JavaScript code execution if an application accepts untrusted input Moderate
CVE-2024-36361 was published for pug (npm) May 24, 2024
davidrunger filipeom
Credited to davidrunger and filipeom
ProTip! Advisories are also available from the GraphQL API