GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of...
High
Unreviewed
CVE-2019-18423
was published
May 24, 2022
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the...
Moderate
Unreviewed
CVE-2020-11765
was published
May 24, 2022
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player...
Moderate
Unreviewed
CVE-2019-19721
was published
May 24, 2022
An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial...
High
Unreviewed
CVE-2020-29040
was published
May 24, 2022
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via ...
High
Unreviewed
CVE-2021-3156
was published
May 24, 2022
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by...
Moderate
Unreviewed
CVE-2020-27171
was published
May 24, 2022
A vulnerability has been identified in Nucleus 4 (All versions < V4.1.0), Nucleus NET (All...
Moderate
Unreviewed
CVE-2020-27736
was published
May 24, 2022
In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off...
Critical
Unreviewed
CVE-2021-31875
was published
May 24, 2022
A security issue in nginx resolver was identified, which might allow an attacker who is able to...
Critical
Unreviewed
CVE-2021-23017
was published
May 24, 2022
Windows Kernel Denial of Service Vulnerability.
Moderate
Unreviewed
CVE-2022-30155
was published
Jun 16, 2022
Crow before v1.0+4 was discovered to contain a buffer overflow via the function qs_parse at...
Critical
Unreviewed
CVE-2022-34970
was published
Aug 5, 2022
An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c....
High
Unreviewed
CVE-2020-27793
was published
Aug 20, 2022
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to...
High
Unreviewed
CVE-2021-3999
was published
Aug 25, 2022
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading...
High
Unreviewed
CVE-2022-3872
was published
Nov 8, 2022
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c....
Moderate
Unreviewed
CVE-2022-3821
was published
Nov 9, 2022
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master...
Moderate
Unreviewed
CVE-2022-36354
was published
Dec 23, 2022
Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
Moderate
Unreviewed
CVE-2023-0818
was published
Feb 14, 2023
wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64
Low
CVE-2023-27477
was published
for
cranelift-codegen
(Rust)
Mar 9, 2023
redis-py Race Condition vulnerability
Moderate
CVE-2023-28858
was published
for
redis
(pip)
Mar 26, 2023
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
High
CVE-2023-28709
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jul 6, 2023
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an...
Critical
Unreviewed
CVE-2023-38429
was published
Jul 18, 2023
An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a...
High
Unreviewed
CVE-2022-33064
was published
Jul 18, 2023
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Low
CVE-2023-41880
was published
for
wasmtime
(Rust)
Sep 14, 2023
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy...
Critical
Unreviewed
CVE-2023-46853
was published
Oct 27, 2023
ProTip!
Advisories are also available from the
GraphQL API