GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,316 advisories
Filter by severity
KubeEdge CloudCore Router memory exhaustion vulnerability
Moderate
CVE-2022-31078
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge Cloud Stream and Edge Stream DoS from large stream message
Moderate
CVE-2022-31079
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
DoS in KubeEdge's Websocket Client in package Viaduct
Moderate
CVE-2022-31080
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit...
Moderate
Unreviewed
CVE-2022-2406
was published
Jul 15, 2022
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption...
High
Unreviewed
CVE-2022-29286
was published
Jul 18, 2022
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2022-22212
was published
Jul 21, 2022
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process...
High
Unreviewed
CVE-2021-46828
was published
Jul 21, 2022
A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group...
High
Unreviewed
CVE-2022-32958
was published
Jul 21, 2022
Teamplus Pro community discussion function has an ‘allocation of resource without limits or...
Moderate
Unreviewed
CVE-2022-35220
was published
Aug 3, 2022
Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’...
Moderate
Unreviewed
CVE-2022-35221
was published
Aug 3, 2022
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to...
Moderate
Unreviewed
CVE-2022-35218
was published
Aug 3, 2022
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to...
Moderate
Unreviewed
CVE-2022-35219
was published
Aug 3, 2022
TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no...
High
Unreviewed
CVE-2022-35506
was published
Aug 4, 2022
A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client...
High
Unreviewed
CVE-2022-35505
was published
Aug 4, 2022
The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL...
High
Unreviewed
CVE-2022-37415
was published
Aug 6, 2022
Rust-WebSocket memory allocation based on untrusted length
High
CVE-2022-35922
was published
for
websocket
(Rust)
Aug 6, 2022
Apache Avro Rust SDK's Reader could consume memory beyond allowed constraints
High
CVE-2022-36124
was published
for
apache-avro
(Rust)
Aug 10, 2022
A vulnerability has been identified in SCALANCE M-800 / S615 (All versions), SCALANCE W-1700 IEEE...
High
Unreviewed
CVE-2022-36324
was published
Aug 11, 2022
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive...
High
Unreviewed
CVE-2022-38155
was published
Aug 12, 2022
OpenZeppelin Contracts ERC165Checker unbounded gas consumption
Moderate
CVE-2022-35915
was published
for
@openzeppelin/contracts
(npm)
Aug 14, 2022
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it...
High
Unreviewed
CVE-2020-14322
was published
Aug 17, 2022
PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux...
Moderate
Unreviewed
CVE-2022-35009
was published
Aug 17, 2022
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via...
Moderate
Unreviewed
CVE-2022-35113
was published
Aug 17, 2022
SWFTools commit 772e55a2 was discovered to contain a stack overflow via __sanitizer:...
Moderate
Unreviewed
CVE-2022-35111
was published
Aug 17, 2022
SWFTools commit 772e55a2 was discovered to contain a stack overflow via vfprintf at /stdio-common...
Moderate
Unreviewed
CVE-2022-35107
was published
Aug 17, 2022
ProTip!
Advisories are also available from the
GraphQL API