GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
892 advisories
Filter by severity
grape subject to Cross-site Scripting
Moderate
CVE-2018-3769
was published
for
grape
(RubyGems)
Aug 13, 2018
active-support impersonates 'activesupport' gem
Critical
CVE-2018-3779
was published
for
active-support
(RubyGems)
Aug 13, 2018
Nokogiri vulnerable to libxml XML Entity Expansion
Moderate
CVE-2015-1819
was published
for
nokogiri
(RubyGems)
Aug 8, 2018
Cross-site request forgery in rails_admin
High
CVE-2016-10522
was published
for
rails_admin
(RubyGems)
Aug 8, 2018
Moderate severity vulnerability that affects safemode
Moderate
GHSA-44vc-fpcg-5cc5
was published
for
safemode
(RubyGems)
Aug 8, 2018
•
withdrawn
High severity vulnerability that affects safemode
High
GHSA-8474-rc7c-wrhp
was published
for
safemode
(RubyGems)
Aug 8, 2018
•
withdrawn
restforce vulnerable to Improper Input Validation
Critical
CVE-2018-3777
was published
for
restforce
(RubyGems)
Aug 3, 2018
High severity vulnerability that affects rubyzip
High
GHSA-3q5q-f79q-7hr2
was published
for
rubyzip
(RubyGems)
Jul 31, 2018
•
withdrawn
Nokogiri implementation of libxslt lacks integer overflow checks
High
CVE-2017-5029
was published
for
nokogiri
(RubyGems)
Jul 31, 2018
Missing Regex anchor in Rack-Cors allows malicious third party site to perform CORS request
High
CVE-2017-11173
was published
for
rack-cors
(RubyGems)
Jul 31, 2018
Json-jwt did not verify the cryptographic signature for data
Moderate
CVE-2018-1000539
was published
for
json-jwt
(RubyGems)
Jul 31, 2018
private_address_check contains race condition
High
CVE-2018-3759
was published
for
private_address_check
(RubyGems)
Jul 31, 2018
radiant vulnerable to Cross-site Scripting
Moderate
CVE-2018-7261
was published
for
radiant
(RubyGems)
Jul 27, 2018
High severity vulnerability that affects jquery-ui
High
GHSA-g8q2-24jh-5hpc
was published
for
jQuery.UI.Combined
(RubyGems)
Jul 27, 2018
•
withdrawn
Low severity vulnerability that affects sensu
Low
CVE-2018-1000060
was published
for
sensu
(RubyGems)
Jul 23, 2018
•
withdrawn
Ciborg gem for Ruby allows local users to write files and gain privileges via Symlink
Moderate
CVE-2014-5003
was published
for
ciborg
(RubyGems)
Jul 23, 2018
Kcapifony gem for Ruby places database user passwords on the command line
High
CVE-2014-5001
was published
for
kcapifony
(RubyGems)
Jul 23, 2018
Sprockets path traversal leads to information leak
High
CVE-2018-3760
was published
for
sprockets
(RubyGems)
Jun 20, 2018
Sinatra Cross-site Scripting vulnerability
Moderate
CVE-2018-11627
was published
for
sinatra
(RubyGems)
Jun 5, 2018
rails-html-sanitizer Cross-site Scripting vulnerability
Moderate
CVE-2018-3741
was published
for
rails-html-sanitizer
(RubyGems)
Apr 26, 2018
Uncontrolled resource consumption in nokogiri
Moderate
CVE-2017-18258
was published
for
nokogiri
(RubyGems)
Apr 13, 2018
Cross-site Scripting in loofah
Moderate
CVE-2018-8048
was published
for
loofah
(RubyGems)
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
High
CVE-2018-3740
was published
for
sanitize
(RubyGems)
Mar 21, 2018
Cap-Strap gem for Ruby places credentials on the useradd command line
High
CVE-2014-4992
was published
for
cap-strap
(RubyGems)
Mar 16, 2018
Doorkeeper is vulnerable to stored XSS and code execution
Moderate
CVE-2018-1000088
was published
for
doorkeeper
(RubyGems)
Mar 13, 2018
ProTip!
Advisories are also available from the
GraphQL API