GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            488 advisories
        Filter by severity
        
      
      
    
                    
                      Prototype Pollution in merge-deep2.
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-23700
                      
                      was published
                        for
                        
                          merge-deep2
                        
                        (npm)
                      Dec 16, 2021 
                    
                  
                    
                      tree-kit vulnerable to Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2021-4278
                      
                      was published
                        for
                        
                          tree-kit
                        
                        (npm)
                      Dec 25, 2022 
                    
                  
                    
                      Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
                    
                      
  Critical
                    
                
                      
                        CVE-2022-37616
                      
                      was published
                        for
                        
                          @xmldom/xmldom
                        
                        (npm)
                      Oct 11, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      safe-eval vulnerable to Prototype Pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2022-25904
                      
                      was published
                        for
                        
                          safe-eval
                        
                        (npm)
                      Dec 20, 2022 
                    
                  
                    
                      Client-Side JavaScript Prototype Pollution in oro/platform
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-43852
                      
                      was published
                        for
                        
                          oro/platform
                        
                        (Composer)
                      Jan 6, 2022 
                    
                  
                    
                      Prototype Pollution in realms-shim
                    
                      
  Critical
                    
                
                      
                        CVE-2021-23543
                      
                      was published
                        for
                        
                          realms-shim
                        
                        (npm)
                      Jan 13, 2022 
                    
                  
                    
                      Prototype Pollution in realms-shim
                    
                      
  Critical
                    
                
                      
                        CVE-2021-23594
                      
                      was published
                        for
                        
                          realms-shim
                        
                        (npm)
                      Jan 12, 2022 
                    
                  
                    
                      Prototype Pollution in object-path-set
                    
                      
  High
                    
                
                      
                        CVE-2021-23507
                      
                      was published
                        for
                        
                          object-path-set
                        
                        (npm)
                      Feb 5, 2022 
                    
                  
                    
                      Prototype Pollution in putil-merge
                    
                      
  High
                    
                
                      
                        CVE-2021-23470
                      
                      was published
                        for
                        
                          putil-merge
                        
                        (npm)
                      Feb 5, 2022 
                    
                  
                    
                      Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0432
                      
                      was published
                      Feb 3, 2022 
                    
                  
                    
                      Prototype Pollution in @strikeentco/set
                    
                      
  High
                    
                
                      
                        CVE-2021-23497
                      
                      was published
                        for
                        
                          @strikeentco/set
                        
                        (npm)
                      Feb 5, 2022 
                    
                  
                    
                      Prototype Pollution in litespeed.js and appwrite/server-ce
                    
                      
  Critical
                    
                
                      
                        CVE-2021-23682
                      
                      was published
                        for
                        
                          appwrite/server-ce
                        
                        (Composer)
                      Feb 17, 2022 
                    
                  
                    
                      Prototype Pollution in object-extend
                    
                      
  Critical
                    
                
                      
                        CVE-2021-23702
                      
                      was published
                        for
                        
                          object-extend
                        
                        (npm)
                      Feb 19, 2022 
                    
                  
                    
                      Prototype Pollution in jquery.cookie
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-23395
                      
                      was published
                        for
                        
                          jquery.cookie
                        
                        (NuGet)
                      Mar 3, 2022 
                    
                  
                    
                      rangy vulnerable to Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2023-26102
                      
                      was published
                        for
                        
                          rangy
                        
                        (npm)
                      Feb 24, 2023 
                    
                  
                    
                      mde utilities contains Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2023-26105
                      
                      was published
                        for
                        
                          utilities
                        
                        (npm)
                      Feb 28, 2023 
                    
                  
                    
                      Prototype Pollution in Visioweb.js 1.10.6 allows attackers to execute XSS on the client system.
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3901
                      
                      was published
                      Feb 20, 2023 
                    
                  
                    
                      dot-lens vulnerable to Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2023-26106
                      
                      was published
                        for
                        
                          dot-lens
                        
                        (npm)
                      Mar 6, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API