GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,245
Erlang
31
GitHub Actions
21
Go
2,010
Maven
5,000+
npm
3,718
NuGet
662
pip
3,391
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
31 advisories
Filter by severity
incorrect order of evaluation of side effects for some builtins
Moderate
CVE-2023-41052
was published
for
vyper
(pip)
Sep 4, 2023
Vyper: reversed order of side effects for some operations
Moderate
CVE-2023-40015
was published
for
vyper
(pip)
Sep 4, 2023
Vyper's nonpayable default functions are sometimes payable
Moderate
CVE-2023-32675
was published
for
vyper
(pip)
May 22, 2023
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The...
Moderate
Unreviewed
CVE-2024-30133
was published
Nov 12, 2024
wasmtime has a runtime crash when combining tail calls with trapping imports
Moderate
CVE-2024-47763
was published
for
wasmtime
(Rust)
Oct 9, 2024
An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a...
Moderate
Unreviewed
CVE-2024-33431
was published
May 1, 2024
Requests `Session` object does not verify requests after making first request with verify=False
Moderate
CVE-2024-35195
was published
for
requests
(pip)
May 20, 2024
eZ Platform Rules to disable executable access are ignored on Platform.sh (eZ Cloud)
Moderate
GHSA-6xch-2vxx-5pvr
was published
for
ezsystems/ezplatform
(Composer)
May 15, 2024
Insufficient control flow management in the Hyperscan Library maintained by Intel(R) before...
Moderate
Unreviewed
CVE-2023-28711
was published
Aug 11, 2023
An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the...
Moderate
Unreviewed
CVE-2022-29609
was published
Apr 20, 2023
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non...
Moderate
Unreviewed
CVE-2020-5753
was published
May 24, 2022
** DISPUTED ** Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency,...
Moderate
Unreviewed
CVE-2021-43979
was published
May 24, 2022
A malicious insider exploiting this vulnerability can circumvent existing security controls put...
Moderate
Unreviewed
CVE-2024-0313
was published
Mar 14, 2024
An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security...
Moderate
Unreviewed
CVE-2021-3011
was published
May 24, 2022
Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log
Moderate
CVE-2023-39152
was published
for
org.jenkins-ci.plugins:gradle
(Maven)
Jul 26, 2023
Always incorrect control flow in github.com/mojocn/base64Captcha
Moderate
CVE-2023-45292
was published
for
github.com/mojocn/base64Captcha
(Go)
Dec 12, 2023
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4
Moderate
CVE-2023-49798
was published
for
@openzeppelin/contracts
(npm)
Dec 12, 2023
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
Moderate
CVE-2023-41338
was published
for
github.com/gofiber/fiber
(Go)
Sep 8, 2023
Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2...
Moderate
Unreviewed
CVE-2022-26841
was published
Feb 16, 2023
Multiple Cisco products are affected by a vulnerability in the Snort application detection engine...
Moderate
Unreviewed
CVE-2021-1236
was published
May 24, 2022
An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to...
Moderate
Unreviewed
CVE-2018-19058
was published
May 13, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
Moderate
CVE-2022-39354
was published
for
evm
(Rust)
Oct 25, 2022
Missing Handler in @scandipwa/magento-scripts
Moderate
CVE-2021-32684
was published
for
@scandipwa/magento-scripts
(npm)
Jun 21, 2021
In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser()...
Moderate
Unreviewed
CVE-2018-19212
was published
May 13, 2022
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
Moderate
CVE-2022-41884
was published
for
tensorflow
(pip)
Nov 21, 2022
ProTip!
Advisories are also available from the
GraphQL API