GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            488 advisories
        Filter by severity
        
      
      
    
                    
                      Prototype Pollution Vulnerability in parse-git-config
                    
                      
  High
                    
                
                      
                        CVE-2025-25975
                      
                      was published
                        for
                        
                          parse-git-config
                        
                        (npm)
                      Mar 12, 2025 
                    
                  
                    
                      canvg Prototype Pollution vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-25977
                      
                      was published
                        for
                        
                          canvg
                        
                        (npm)
                      Mar 10, 2025 
                    
                  
                    
                      Vue I18n Allows Prototype Pollution in `handleFlatJson`
                    
                      
  High
                    
                
                      
                        CVE-2025-27597
                      
                      was published
                        for
                        
                          @intlify/core
                        
                        (npm)
                      Mar 7, 2025 
                    
                  
                    
                      Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-25015
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-12629
                      
                      was published
                      Feb 12, 2025 
                    
                  
                    
                      In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-11628
                      
                      was published
                      Feb 12, 2025 
                    
                  
                    
                      A prototype pollution in the function lib.parse of dot-properties v1.0.1 allows attackers to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57084
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      @stryker-mutator/util vulnerable to Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-57085
                      
                      was published
                        for
                        
                          @stryker-mutator/util
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57074
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57076
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      utils-extend Prototype Pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2024-57077
                      
                      was published
                        for
                        
                          utils-extend
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      @zag-js/core prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-57079
                      
                      was published
                        for
                        
                          @zag-js/core
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57081
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      @rpldy/uploader prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-57082
                      
                      was published
                        for
                        
                          @rpldy/uploader
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      node-opcua-alarm-condition prototype pollution vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-57086
                      
                      was published
                        for
                        
                          node-opcua-alarm-condition
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.merge function of cli-util v1.1.27 allows attackers to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57078
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      @ndhoule/defaults prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-57066
                      
                      was published
                        for
                        
                          @ndhoule/defaults
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57069
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57067
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57064
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57071
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-57063
                      
                      was published
                      Feb 6, 2025 
                    
                  
                    
                      module-from-string prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-57072
                      
                      was published
                        for
                        
                          module-from-string
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API