GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
119 advisories
Filter by severity
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
High
CVE-2016-6817
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Aubio is vulnerable to denial of service via aubio_pitch_set_unit function
High
CVE-2018-14522
was published
for
aubio
(pip)
May 14, 2022
ChakraCore RCE Vulnerability
High
CVE-2017-11911
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
ChakraCore vulnerable to privilege escalation due to exposure from scriptFunction
High
CVE-2017-11914
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
ChakraCore vulnerable to remote code execution
High
CVE-2017-11909
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
ChakraCore vulnerable to remote code execution
High
CVE-2017-11893
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
High
CVE-2018-17847
was published
for
golang.org/x/net
(Go)
May 13, 2022
golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer
High
CVE-2018-17143
was published
for
golang.org/x/net
(Go)
May 13, 2022
Apache Tomcat DoS via Malicious Get Request
High
CVE-2002-2272
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
ipld/go-codec-dagpb panics when processing certain blocks
High
GHSA-g3vv-g2j5-45f2
was published
for
github.com/ipld/go-codec-dagpb
(Go)
Apr 8, 2022
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
High
CVE-2020-13934
was published
for
org.apache.tomcat:tomcat
(Maven)
Feb 8, 2022
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
High
CVE-2017-12862
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
High
CVE-2017-12601
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
Memory corruption when returning a literal struct with a private call inside of it
High
CVE-2021-41121
was published
for
vyper
(pip)
Oct 12, 2021
crossbeam-channel Undefined Behavior before v0.4.4
High
CVE-2020-15254
was published
for
crossbeam-channel
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API