GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
87 advisories
Filter by severity
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with...
Moderate
Unreviewed
CVE-2024-11407
was published
Nov 26, 2024
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an...
Moderate
Unreviewed
CVE-2024-11176
was published
Nov 20, 2024
Vyper's `_abi_decode` input not validated in complex expressions
Moderate
CVE-2023-42460
was published
for
vyper
(pip)
Sep 26, 2023
missing clamps for decimal args in external functions
Moderate
CVE-2021-41122
was published
for
vyper
(pip)
Oct 6, 2021
Segfault due to negative splits in `SplitV`
Moderate
CVE-2021-41222
was published
for
tensorflow
(pip)
Nov 10, 2021
Weight not properly refunded after EVM execution
Moderate
CVE-2022-39242
was published
for
pallet-ethereum
(Rust)
Sep 23, 2022
Frontier's modexp precompile is slow for even modulus
High
CVE-2023-28431
was published
for
pallet-evm-precompile-modexp
(Rust)
Mar 21, 2023
A flaw in DRBG number generation within the Network Security Services (NSS) library where the...
Moderate
Unreviewed
CVE-2017-5462
was published
May 13, 2022
An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the...
Moderate
Unreviewed
CVE-2023-36980
was published
Sep 11, 2023
An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect...
Critical
Unreviewed
CVE-2024-36736
was published
Jun 6, 2024
Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and...
Critical
Unreviewed
CVE-2024-23981
was published
Aug 14, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: don't allow...
High
Unreviewed
CVE-2024-41011
was published
Jul 18, 2024
evmos allows transferring unvested tokens after delegations
Low
CVE-2024-32873
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
In the Linux kernel, the following vulnerability has been resolved:
btrfs: zoned: fix...
Moderate
Unreviewed
CVE-2024-42231
was published
Jul 30, 2024
Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of...
High
Unreviewed
CVE-2024-6287
was published
Jun 24, 2024
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from...
Moderate
Unreviewed
CVE-2019-16347
was published
May 24, 2022
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from...
Moderate
Unreviewed
CVE-2019-16346
was published
May 24, 2022
nistec has Incorrect Calculation in Multiplication of unreduced P-256 scalars
High
CVE-2023-24533
was published
for
filippo.io/nistec
(Go)
Mar 1, 2023
Incorrect Calculation in github.com/open-policy-agent/opa
Moderate
CVE-2022-23628
was published
for
github.com/open-policy-agent/opa
(Go)
Feb 9, 2022
Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with...
Moderate
Unreviewed
CVE-2023-43490
was published
Mar 14, 2024
A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the...
High
Unreviewed
CVE-2023-2423
was published
Aug 8, 2023
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before...
High
Unreviewed
CVE-2023-35848
was published
Jun 19, 2023
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font-...
Moderate
Unreviewed
CVE-2023-3161
was published
Jun 12, 2023
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading...
High
Unreviewed
CVE-2019-17514
was published
May 24, 2022
Miscompilation of `i8x16.swizzle` and `select` with v128 inputs
Moderate
CVE-2022-31104
was published
for
cranelift-codegen
(Rust)
Jun 29, 2022
ProTip!
Advisories are also available from the
GraphQL API