Essential vulnerability data for your ecosystem
Advisories is a comprehensive open API service that provides professional-quality security vulnerability metadata for numerous open source software ecosystems for free
Comprehensive vulnerability database
Access unified vulnerability data from multiple sources including package registries, software repositories, and vulnerability databases, giving you a comprehensive view of security threats across your entire open source stack.
Latest vulnerabilities
View allOpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
Get complete security visibility
Access unified vulnerability data from multiple sources including package registries, software repositories, and vulnerability databases, giving you a comprehensive view of security threats across your entire open source stack.
Stay ahead of security risks
Identify which packages and projects in your dependencies are affected by security advisories, empowering you to make informed decisions and address vulnerabilities before they become critical threats to your systems.
Integrate seamlessly into your workflow
Enjoy 5,000 requests per hour rate limits and comprehensive REST API documentation, allowing you to easily incorporate security intelligence into your development and security management processes.
Get started
Find a project and see it in our dashboard, with statistics on responsiveness, productivity, finance and more available to compare over time.