GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            159 advisories
        Filter by severity
        
      
      
    
                    
                      happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62410
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57347
                      
                      was published
                      Sep 24, 2025 
                    
                  
                    
                      Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2011-10019
                      
                      was published
                      Aug 13, 2025 
                    
                  
                    
                      billboard.js allows prototype pollution via the function generate
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49223
                      
                      was published
                        for
                        
                          billboard.js
                        
                        (npm)
                      Jun 4, 2025 
                    
                  
                    
                      A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-25014
                      
                      was published
                      May 6, 2025 
                    
                  
                    
                      A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-24292
                      
                      was published
                      Mar 28, 2025 
                    
                  
                    
                      Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-25015
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      utils-extend Prototype Pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2024-57077
                      
                      was published
                        for
                        
                          utils-extend
                        
                        (npm)
                      Feb 6, 2025 
                    
                  
                    
                      Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-56059
                      
                      was published
                      Dec 18, 2024 
                    
                  
                    
                      Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-52441
                      
                      was published
                      Nov 20, 2024 
                    
                  
                    
                      DOMPurify vulnerable to tampering by prototype polution
                    
                      
  Critical
                    
                
                      
                        CVE-2024-48910
                      
                      was published
                        for
                        
                          dompurify
                        
                        (npm)
                      Oct 31, 2024 
                    
                  
                    
                      Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-45435
                      
                      was published
                      Aug 29, 2024 
                    
                  
                    
                      A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-37287
                      
                      was published
                      Aug 13, 2024 
                    
                  
                    
                      Prototype pollution in izatop bunt
                    
                      
  Critical
                    
                
                      
                        CVE-2024-38989
                      
                      was published
                        for
                        
                          @bunt/app
                        
                        (npm)
                      Aug 12, 2024 
                    
                  
                    
                      Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39011
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38983
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-36572
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39010
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38984
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39012
                      
                      was published
                      Jul 30, 2024 
                    
                  
                    
                      ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39014
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39013
                      
                      was published
                      Jul 1, 2024 
                    
                  
                    
                      jsonic was discovered to contain a prototype pollution via the function empty.
                    
                      
  Critical
                    
                
                      
                        CVE-2024-38993
                      
                      was published
                        for
                        
                          jsonic
                        
                        (npm)
                      Jul 1, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Blackprint @blackprint/engine Prototype Pollution issue
                    
                      
  Critical
                    
                
                      
                        CVE-2024-24294
                      
                      was published
                        for
                        
                          @blackprint/engine
                        
                        (npm)
                      May 20, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API