GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
UltraJSON vulnerable to Out-of-bounds Write
Moderate
CVE-2021-45958
was published
for
ujson
(pip)
Jan 21, 2022
Interpreter crash from `tf.io.decode_raw`
Moderate
CVE-2021-29614
was published
for
tensorflow
(pip)
May 21, 2021
Incomplete validation in `SparseAdd`
Moderate
CVE-2021-29609
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `Transpose`
Moderate
CVE-2021-41216
was published
for
tensorflow
(pip)
Nov 10, 2021
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Moderate
CVE-2024-29133
was published
for
org.apache.commons:commons-configuration2
(Maven)
Mar 21, 2024
Segfault and data corruption in tensorflow-lite
Moderate
CVE-2020-15207
was published
for
tensorflow
(pip)
Sep 25, 2020
Heap buffer overflow in Tensorflow
Moderate
CVE-2020-15201
was published
for
tensorflow
(pip)
Sep 25, 2020
Heap buffer overflow in Tensorflow
Moderate
CVE-2020-15195
was published
for
tensorflow
(pip)
Sep 25, 2020
Out of bounds access in tensorflow-lite
Moderate
CVE-2020-15211
was published
for
tensorflow
(pip)
Sep 25, 2020
Elasticsearch StackOverflow vulnerability
Moderate
CVE-2024-37280
was published
for
org.elasticsearch:elasticsearch
(Maven)
Jun 13, 2024
Heap-based Buffer Overflow in MicroPython
Moderate
CVE-2024-8946
was published
for
micropython-copy
(pip)
Sep 17, 2024
heap-buffer-overflow in MicroPython
Moderate
CVE-2024-8948
was published
for
micropython-copy
(pip)
Sep 17, 2024
Miniscript allows stack consumption
Moderate
CVE-2024-44073
was published
for
miniscript
(Rust)
Aug 19, 2024
Snakeyaml vulnerable to Stack overflow leading to denial of service
Moderate
CVE-2022-41854
was published
for
org.yaml:snakeyaml
(Maven)
Nov 11, 2022
json-path Out-of-bounds Write vulnerability
Moderate
CVE-2023-51074
was published
for
com.jayway.jsonpath:json-path
(Maven)
Dec 27, 2023
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Moderate
CVE-2024-29131
was published
for
org.apache.commons:commons-configuration2
(Maven)
Mar 21, 2024
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38751
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38749
was published
for
be.cylab:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38752
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38750
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
Moderate
CVE-2023-50711
was published
for
vmm-sys-util
(Rust)
Jan 2, 2024
Heap buffer overflow in CefSharp
Moderate
CVE-2020-15999
was published
for
CefSharp.Common
(NuGet)
Oct 27, 2020
Memory over-allocation in evm crate
Moderate
CVE-2021-29511
was published
for
evm
(Rust)
Jan 30, 2024
ProTip!
Advisories are also available from the
GraphQL API