GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
High
CVE-2023-31146
was published
for
vyper
(pip)
May 12, 2023
Out of bounds read and write in Tensorflow
High
CVE-2022-23574
was published
for
tensorflow
(pip)
Feb 9, 2022
Out of bounds write in Tensorflow
High
CVE-2022-23566
was published
for
tensorflow
(pip)
Feb 9, 2022
Read and Write outside of bounds in TensorFlow
High
CVE-2022-23560
was published
for
tensorflow
(pip)
Feb 9, 2022
Heap buffer overflow in `FractionalAvgPoolGrad`
High
CVE-2021-37651
was published
for
tensorflow
(pip)
Aug 25, 2021
Segfault and heap buffer overflow in `{Experimental,}DatasetToTFRecord`
High
CVE-2021-37650
was published
for
tensorflow
(pip)
Aug 25, 2021
Access to invalid memory during shape inference in `Cudnn*` ops
High
CVE-2021-41221
was published
for
tensorflow
(pip)
Nov 10, 2021
Data corruption in tensorflow-lite
High
CVE-2020-15208
was published
for
tensorflow
(pip)
Sep 25, 2020
Segmentation fault in tensorflow-lite
High
CVE-2020-15210
was published
for
tensorflow
(pip)
Sep 25, 2020
protobuf susceptible to buffer overflow
High
CVE-2015-5237
was published
for
Google.Protobuf
(Composer)
May 13, 2022
concat built-in can corrupt memory in vyper
High
CVE-2024-22419
was published
for
vyper
(pip)
Jan 19, 2024
Heap-based Buffer Overflow in sqlite-vec
High
CVE-2024-46488
was published
for
sqlite-vec
(RubyGems)
Sep 25, 2024
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
High
CVE-2020-36242
was published
for
cryptography
(pip)
Feb 10, 2021
bsdiff4 out-of-bounds write via patch file
High
CVE-2020-15904
was published
for
bsdiff4
(pip)
May 24, 2022
opencv-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
High
GHSA-qr4w-53vh-m672
was published
for
opencv-python
(pip)
Aug 30, 2024
opencv-contrib-python bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
High
GHSA-cxjf-x6jp-p7mc
was published
for
opencv-contrib-python
(pip)
Aug 30, 2024
opencv-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
High
GHSA-jh2j-j4j9-crg3
was published
for
opencv-python-headless
(pip)
Aug 30, 2024
opencv-contrib-python-headless bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863
High
GHSA-w2pj-9cgh-mq2c
was published
for
opencv-contrib-python-headless
(pip)
Aug 30, 2024
ProTip!
Advisories are also available from the
GraphQL API