GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,957
Maven
5,000+
npm
4,607
NuGet
788
pip
4,307
Pub
12
RubyGems
984
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
Maker.js has Unsafe Property Copying in makerjs.extendObject
Moderate
CVE-2026-24888
was published
for
makerjs
(npm)
Jan 29, 2026
NocoDB has Prototype Pollution in Connection Test Endpoint, Leading to DoS
Moderate
CVE-2026-24766
was published
for
nocodb
(npm)
Jan 28, 2026
JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
Moderate
CVE-2025-61140
was published
for
jsonpath
(npm)
Jan 28, 2026
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
Moderate
CVE-2025-13465
was published
for
lodash
(npm)
Jan 21, 2026
js-yaml has prototype pollution in merge (<<)
Moderate
CVE-2025-64718
was published
for
js-yaml
(npm)
Nov 14, 2025
rollbar vulnerable to Prototype Pollution in merge()
Moderate
CVE-2025-62517
was published
for
rollbar
(npm)
Oct 23, 2025
Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
Moderate
CVE-2025-62374
was published
for
parse
(npm)
Oct 14, 2025
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
Moderate
CVE-2025-3193
was published
for
algoliasearch-helper
(npm)
Sep 27, 2025
ts-fns has prototype pollution vulnerability
Moderate
CVE-2025-57351
was published
for
ts-fns
(npm)
Sep 24, 2025
json-schema-editor-visual vulnerable to prototype pollution
Moderate
CVE-2025-57320
was published
for
json-schema-editor-visual
(npm)
Sep 24, 2025
parse is vulnerable to prototype pollution
Moderate
CVE-2025-57324
was published
for
parse
(npm)
Sep 24, 2025
counterpart vulnerable to prototype pollution
Moderate
CVE-2025-57354
was published
for
counterpart
(npm)
Sep 24, 2025
messageformat prototype pollution vulnerability
Moderate
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
CSVTOJSON has a prototype pollution vulnerability
Moderate
CVE-2025-57350
was published
for
csvtojson
(npm)
Sep 24, 2025
@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
Moderate
CVE-2025-53626
was published
for
@pdfme/common
(npm)
Jul 10, 2025
radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Moderate
CVE-2025-48054
was published
for
radashi
(npm)
May 27, 2025
estree-util-value-to-estree allows prototype pollution in generated ESTree
Moderate
CVE-2025-32014
was published
for
estree-util-value-to-estree
(npm)
Apr 7, 2025
tarteaucitron.js allows prototype pollution via custom text injection
Moderate
CVE-2025-31475
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
expand-object Vulnerable to Prototype Pollution via the expand() Function
Moderate
CVE-2025-3197
was published
for
expand-object
(npm)
Apr 4, 2025
Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo
Moderate
CVE-2024-21548
was published
for
bun
(npm)
Dec 18, 2024
@intlify/shared Prototype Pollution vulnerability
Moderate
CVE-2024-52810
was published
for
@intlify/shared
(npm)
Dec 2, 2024
SAP HANA Node.js client package vulnerable to Prototype Pollution
Moderate
CVE-2024-45277
was published
for
@sap/hana-client
(npm)
Oct 8, 2024
@cat5th/key-serializer Prototype Pollution vulnerability
Moderate
CVE-2024-39018
was published
for
@cat5th/key-serializer
(npm)
Jul 1, 2024
ag-grid packages vulnerable to Prototype Pollution
Moderate
CVE-2024-39001
was published
for
@ag-grid-enterprise/charts
(npm)
Jul 1, 2024
adolph_dudu ratio-swiper was discovered to contain a prototype pollution via the function extendDefaults
Moderate
CVE-2024-38997
was published
for
@adolph_dudu/ratio-swiper
(npm)
Jul 1, 2024
ProTip!
Advisories are also available from the
GraphQL API