GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
63 advisories
Filter by severity
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95....
Moderate
Unreviewed
CVE-2019-20051
was published
May 24, 2022
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can...
High
Unreviewed
CVE-2021-44490
was published
Apr 16, 2022
STB v2.27 was discovered to contain an integer shift of invalid size in the component...
High
Unreviewed
CVE-2022-28048
was published
Apr 16, 2022
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using...
High
Unreviewed
CVE-2021-44504
was published
Apr 16, 2022
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can...
High
Unreviewed
CVE-2021-44491
was published
Apr 16, 2022
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect...
Moderate
Unreviewed
CVE-2021-3114
was published
May 24, 2022
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that...
Moderate
Unreviewed
CVE-2016-9377
was published
May 17, 2022
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode...
High
Unreviewed
CVE-2017-0342
was published
May 17, 2022
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts...
High
Unreviewed
CVE-2021-45960
was published
Feb 10, 2022
ati_2d_blt in hw/display/ati_2d.c in QEMU 4.2.1 can encounter an outside-limits situation in a...
Moderate
Unreviewed
CVE-2020-27616
was published
May 24, 2022
The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an...
High
Unreviewed
CVE-2021-3004
was published
May 24, 2022
A vulnerability has been identified in SCALANCE XM-400 Family (All versions < V6.4), SCALANCE XR...
High
Unreviewed
CVE-2020-28393
was published
May 24, 2022
This vulnerability allows local attackers to escalate privileges on affected installations of...
High
Unreviewed
CVE-2021-31440
was published
May 24, 2022
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read...
Moderate
Unreviewed
CVE-2021-29945
was published
May 24, 2022
In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events...
Moderate
Unreviewed
CVE-2021-34573
was published
May 24, 2022
In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before...
High
Unreviewed
CVE-2019-5607
was published
May 24, 2022
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x...
High
Unreviewed
CVE-2022-26517
was published
May 6, 2022
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel...
Moderate
Unreviewed
CVE-2022-29978
was published
May 12, 2022
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote...
Moderate
Unreviewed
CVE-2016-7433
was published
May 13, 2022
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan...
High
Unreviewed
CVE-2018-18225
was published
May 13, 2022
ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE...
Moderate
Unreviewed
CVE-2018-16781
was published
May 13, 2022
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote...
Moderate
Unreviewed
CVE-2011-3062
was published
May 13, 2022
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive...
High
Unreviewed
CVE-2017-12135
was published
May 13, 2022
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line...
High
Unreviewed
CVE-2018-11790
was published
May 13, 2022
A vulnerability in certain IPv4 fragment-processing functions of Cisco Remote PHY Software could...
High
Unreviewed
CVE-2018-15391
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API