GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            241 advisories
        Filter by severity
        
      
      
    
                    
                      Devise does not properly perform type conversion when performing database queries
                    
                      
  Moderate
                    
                
                      
                        CVE-2013-0233
                      
                      was published
                        for
                        
                          devise
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      extlib does not properly restrict casts of string values
                    
                      
  High
                    
                
                      
                        CVE-2013-1802
                      
                      was published
                        for
                        
                          extlib
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      crack does not properly restrict casts of string values
                    
                      
  High
                    
                
                      
                        CVE-2013-1800
                      
                      was published
                        for
                        
                          crack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Unsound casting in flatbuffers
                    
                      
  Critical
                    
                
                      
                        CVE-2019-25004
                      
                      was published
                        for
                        
                          flatbuffers
                        
                        (Rust)
                      Aug 25, 2021 
                    
                  
                    
                      Dangling reference in flatbuffers
                    
                      
  High
                    
                
                      
                        CVE-2020-35864
                      
                      was published
                        for
                        
                          flatbuffers
                        
                        (Rust)
                      Aug 25, 2021 
                    
                  
                    
                      os_str_bytes relies on undefined behavior of `char::from_u32_unchecked`
                    
                      
  High
                    
                
                      
                        CVE-2020-35865
                      
                      was published
                        for
                        
                          os_str_bytes
                        
                        (Rust)
                      Aug 25, 2021 
                    
                  
                    
                      Unaligned memory access in rand_core
                    
                      
  Critical
                    
                
                      
                        CVE-2020-25576
                      
                      was published
                        for
                        
                          rand_core
                        
                        (Rust)
                      Aug 25, 2021 
                    
                  
                    
                      Cachet vulnerable to forced reinstall
                    
                      
  High
                    
                
                      
                        CVE-2021-39173
                      
                      was published
                        for
                        
                          cachethq/cachet
                        
                        (Composer)
                      Aug 30, 2021 
                    
                  
                    
                      An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-43537
                      
                      was published
                      Dec 9, 2021 
                    
                  
                    
                      The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-39989
                      
                      was published
                      Jan 4, 2022 
                    
                  
                    
                      Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-30300
                      
                      was published
                      Jan 14, 2022 
                    
                  
                    
                      A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-3578
                      
                      was published
                      Feb 17, 2022 
                    
                  
                    
                      Improperly checked metadata on tools/armour itemstacks received from the client
                    
                      
  High
                    
                
                      
                        GHSA-46c5-pfj8-fv65
                      
                      was published
                        for
                        
                          pocketmine/pocketmine-mp
                        
                        (Composer)
                      Mar 18, 2022 
                    
                  
                    
                      A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-28275
                      
                      was published
                      Mar 24, 2022 
                    
                  
                    
                      A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0322
                      
                      was published
                      Mar 26, 2022 
                    
                  
                    
                      Possible out of bounds access due to improper input validation during graphics profiling in...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-35105
                      
                      was published
                      Apr 2, 2022 
                    
                  
                    
                      Possible buffer overflow to improper validation of hash segment of file while allocating memory...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-35110
                      
                      was published
                      Apr 2, 2022 
                    
                  
                    
                      An exploitable type confusion vulnerability exists in the way Foxit PDF Reader version 9.0.1.1049...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-3843
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-3106
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6992
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-4944
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2015-5219
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-7156
                      
                      was published
                      May 13, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API