GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
184 advisories
Filter by severity
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local...
High
Unreviewed
CVE-2022-41668
was published
Nov 4, 2022
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions...
High
Unreviewed
CVE-2015-5219
was published
May 13, 2022
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID...
High
Unreviewed
CVE-2022-40531
was published
Mar 10, 2023
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a...
High
Unreviewed
CVE-2018-14379
was published
May 13, 2022
Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and...
High
Unreviewed
CVE-2021-30300
was published
Jan 14, 2022
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte...
High
Unreviewed
CVE-2022-32547
was published
Jun 17, 2022
Dangling reference in flatbuffers
High
CVE-2020-35864
was published
for
flatbuffers
(Rust)
Aug 25, 2021
os_str_bytes relies on undefined behavior of `char::from_u32_unchecked`
High
CVE-2020-35865
was published
for
os_str_bytes
(Rust)
Aug 25, 2021
Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder
High
CVE-2022-1642
was published
for
github.com/apple/swift-corelibs-foundation
(Swift)
Jun 7, 2023
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases,...
High
Unreviewed
CVE-2020-10735
was published
Sep 10, 2022
Weaviate denial of service vulnerability
High
CVE-2023-38976
was published
for
github.com/weaviate/weaviate
(Go)
Aug 22, 2023
extlib does not properly restrict casts of string values
High
CVE-2013-1802
was published
for
extlib
(RubyGems)
Oct 24, 2017
pg-native and libpq vulnerable to uncontrolled resource consumption
High
CVE-2022-25852
was published
for
libpq
(npm)
Jun 18, 2022
crack does not properly restrict casts of string values
High
CVE-2013-1800
was published
for
crack
(RubyGems)
Oct 24, 2017
Incorrect Privilege Assignment in Jenkins Script Security Plugin
High
CVE-2019-10355
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A...
High
Unreviewed
CVE-2019-5053
was published
May 24, 2022
Memory corruption due to incorrect type conversion or cast in audio while using audio playback...
High
Unreviewed
CVE-2022-33301
was published
Apr 13, 2023
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic...
High
Unreviewed
CVE-2023-28162
was published
Jun 2, 2023
Memory corruption in Audio due to incorrect type cast during audio use-cases.
High
Unreviewed
CVE-2022-33240
was published
Jun 6, 2023
Memory corruption in Video while calling APIs with different instance ID than the one received in...
High
Unreviewed
CVE-2023-21638
was published
Jul 4, 2023
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201...
High
Unreviewed
CVE-2023-45204
was published
Oct 10, 2023
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to...
High
Unreviewed
CVE-2018-6157
was published
May 24, 2022
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write...
High
Unreviewed
CVE-2023-21651
was published
Aug 8, 2023
Memory corruption in Graphics while importing a file.
High
Unreviewed
CVE-2023-21665
was published
May 2, 2023
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
High
Unreviewed
CVE-2023-33101
was published
Apr 1, 2024
ProTip!
Advisories are also available from the
GraphQL API