GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            488 advisories
        Filter by severity
        
      
      
    
                    
                      @75lb/deep-merge Prototype Pollution vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-38986
                      
                      was published
                        for
                        
                          @75lb/deep-merge
                        
                        (npm)
                      Jul 30, 2024 
                    
                  
                    
                      A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-33519
                      
                      was published
                      Jul 24, 2024 
                    
                  
                    
                      A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-22443
                      
                      was published
                      Jul 24, 2024 
                    
                  
                    
                      adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39853
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      @cat5th/key-serializer Prototype Pollution vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-39018
                      
                      was published
                        for
                        
                          @cat5th/key-serializer
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39016
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39014
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      robinweser fast-loops vulnerable to prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-39008
                      
                      was published
                        for
                        
                          fast-loops
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39013
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      ag-grid packages vulnerable to Prototype Pollution
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-39001
                      
                      was published
                        for
                        
                          @ag-grid-enterprise/charts
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39000
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39003
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      jrburke requirejs vulnerable to prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-38999
                      
                      was published
                        for
                        
                          requirejs
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function config....
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38998
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      adolph_dudu ratio-swiper was discovered to contain a prototype pollution via the function extendDefaults
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-38997
                      
                      was published
                        for
                        
                          @adolph_dudu/ratio-swiper
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      Prototype pollution in ag-grid-community via the _.mergeDeep function
                    
                      
  High
                    
                
                      
                        CVE-2024-38996
                      
                      was published
                        for
                        
                          ag-grid-community
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      @amoy/common v was discovered to contain a prototype pollution via the function extend
                    
                      
  High
                    
                
                      
                        CVE-2024-38994
                      
                      was published
                        for
                        
                          @amoy/common
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      jsonic was discovered to contain a prototype pollution via the function empty.
                    
                      
  Critical
                    
                
                      
                        CVE-2024-38993
                      
                      was published
                        for
                        
                          jsonic
                        
                        (npm)
                      Jul 1, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      frappejs was discovered to contain a prototype pollution via the function registerView
                    
                      
  High
                    
                
                      
                        CVE-2024-38992
                      
                      was published
                        for
                        
                          @airvertco/frappejs
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      akbr patch-into was discovered to contain a prototype pollution via the function patchInto
                    
                      
  High
                    
                
                      
                        CVE-2024-38991
                      
                      was published
                        for
                        
                          @akbr/patch-into
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      @aofl/cli-lib Prototype Pollution vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-38987
                      
                      was published
                        for
                        
                          @aofl/cli-lib
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      @akbr/update Prototype Pollution
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-36578
                      
                      was published
                        for
                        
                          @akbr/update
                        
                        (npm)
                      Jun 17, 2024 
                    
                  
                    
                      Object Resolver Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-36577
                      
                      was published
                        for
                        
                          @apphp/object-resolver
                        
                        (npm)
                      Jun 17, 2024 
                    
                  
                    
                      flatten-json Prototype Pollution
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-36574
                      
                      was published
                        for
                        
                          @allanlancioni/flatten-json
                        
                        (npm)
                      Jun 17, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API