GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,661
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
ncurses exposes uninitialized memory in string reading functions
Moderate
GHSA-x77x-7mmh-cxv3
was published
for
ncurses
(Rust)
Oct 22, 2025
webp crate may expose memory contents when encoding an image
Moderate
GHSA-9q78-27f3-2jmh
was published
for
webp
(Rust)
Aug 29, 2025
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
Moderate
CVE-2025-48072
was published
for
OpenEXR
(pip)
Jul 31, 2025
OpenZeppelin Contracts Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
Moderate
CVE-2025-54070
was published
for
@openzeppelin/contracts
(npm)
Jul 17, 2025
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
Moderate
GHSA-9cc5-2pq7-hfj8
was published
for
xmas-elf
(Rust)
Mar 26, 2025
Browsershot Improper Input Validation vulnerability
Moderate
CVE-2024-21549
was published
for
spatie/browsershot
(Composer)
Dec 20, 2024
`ruzstd` uninit and out-of-bounds memory reads
Moderate
GHSA-x3f4-45xf-rjm7
was published
for
ruzstd
(Rust)
Dec 2, 2024
wasm3 uncontrolled memory allocation vulnerability
Moderate
CVE-2024-27529
was published
for
github.com/shareup/wasm-interpreter-apple
(pip)
Nov 9, 2024
Exiv2 has an out-of-bounds read in QuickTimeVideo::NikonTagsDecoder
Moderate
CVE-2024-24826
was published
for
exiv2
(pip)
Oct 17, 2024
PyMongo Out-of-bounds Read in the bson module
Moderate
CVE-2024-5629
was published
for
pymongo
(pip)
Jun 5, 2024
iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash
Moderate
CVE-2024-36124
was published
for
org.iq80.snappy:snappy
(Maven)
Jun 4, 2024
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
Moderate
CVE-2024-29857
was published
for
BouncyCastle
(Maven)
May 14, 2024
PyMongo Out-of-bounds Read in the bson module
Moderate
GHSA-cr6f-gf5w-vhrc
was published
for
pymongo
(pip)
Apr 6, 2024
•
withdrawn
Onnx Out-of-bounds Read vulnerability
Moderate
CVE-2024-27319
was published
for
onnx
(pip)
Feb 23, 2024
PaddlePaddle segfault in paddle.mode
Moderate
CVE-2023-38678
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
Versionize::deserialize implementation for FamStructWrapper<T> is lacking bound checks, potentially leading to out of bounds memory accesses
Moderate
CVE-2023-28448
was published
for
versionize
(Rust)
Mar 24, 2023
partial_sort contains Out-of-bounds Read in release mode
Moderate
GHSA-5x36-7567-3cw6
was published
for
partial_sort
(Rust)
Feb 28, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2
Moderate
GHSA-hxp2-xqf3-v83h
was published
for
github.com/pion/dtls
(Go)
Feb 7, 2023
Cap'n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-list
Moderate
CVE-2022-46149
was published
for
capnp
(Rust)
Dec 5, 2022
Tensorflow vulnerable to Out-of-Bounds Read
Moderate
CVE-2022-41880
was published
for
tensorflow
(pip)
Nov 22, 2022
Heap overflow in `QuantizeAndDequantizeV2`
Moderate
CVE-2022-41910
was published
for
tensorflow
(pip)
Nov 21, 2022
`FractionalMaxPoolGrad` Heap out of bounds read
Moderate
CVE-2022-41897
was published
for
tensorflow
(pip)
Nov 21, 2022
`MirrorPadGrad` heap out of bounds read
Moderate
CVE-2022-41895
was published
for
tensorflow
(pip)
Nov 21, 2022
ProTip!
Advisories are also available from the
GraphQL API