GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,957
Maven
5,000+
npm
4,607
NuGet
787
pip
4,306
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
183 advisories
Filter by severity
AdonisJS multipart body parsing has Prototype Pollution issue
High
CVE-2026-25754
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
seroval Affected by Prototype Pollution via JSON Deserialization
High
CVE-2026-23736
was published
for
seroval
(npm)
Jan 21, 2026
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
High
CVE-2025-8101
was published
for
linkifyjs
(npm)
Jul 26, 2025
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
High
CVE-2025-68130
was published
for
@trpc/server
(npm)
Dec 16, 2025
Vuetify has a Prototype Pollution vulnerability
High
CVE-2025-8083
was published
for
vuetify
(npm)
Dec 12, 2025
angular Prototype Pollution vulnerability
High
CVE-2019-10768
was published
for
angular
(npm)
Nov 20, 2019
expr-eval vulnerable to Prototype Pollution
High
CVE-2025-13204
was published
for
expr-eval
(npm)
Nov 14, 2025
Prototype Pollution in jquery-bbq
High
CVE-2021-20086
was published
for
jquery-bbq
(npm)
May 24, 2021
`sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
High
CVE-2025-62381
was published
for
sveltekit-superforms
(npm)
Oct 15, 2025
Prototype Pollution in @hapi/subtext
High
GHSA-g9cg-h3jm-cwrc
was published
for
@hapi/pez
(npm)
Sep 3, 2020
dref is vulnerable to prototype pollution
High
CVE-2025-26278
was published
for
dref
(npm)
Sep 25, 2025
csvjson vulnerable to prototype injection
High
CVE-2025-57318
was published
for
csvjson
(npm)
Sep 24, 2025
mpregular vulnerable to prototype pollution
High
CVE-2025-57323
was published
for
mpregular
(npm)
Sep 24, 2025
devalue prototype pollution vulnerability
High
CVE-2025-57820
was published
for
devalue
(npm)
Aug 26, 2025
Prototype Pollution in jquery-deparam
High
CVE-2021-20087
was published
for
jquery-deparam
(npm)
May 24, 2021
content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE
High
CVE-2025-55164
was published
for
content-security-policy-parser
(npm)
Aug 12, 2025
js-toml Prototype Pollution Vulnerability
High
CVE-2025-54803
was published
for
js-toml
(npm)
Aug 4, 2025
@stryker-mutator/util vulnerable to Prototype Pollution
High
CVE-2024-57085
was published
for
@stryker-mutator/util
(npm)
Feb 6, 2025
@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
High
CVE-2025-34146
was published
for
@nyariv/sandboxjs
(npm)
Jul 31, 2025
Synchrony deobfuscator prototype pollution vulnerability leading to arbitrary code execution
High
CVE-2023-45811
was published
for
deobfuscator
(npm)
Oct 18, 2023
Duplicate Advisory: Prototype Pollution in min-dash
High
GHSA-fm93-fhh2-cg2c
was published
for
min-dash
(npm)
Jan 27, 2022
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API