GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,128 advisories
Filter by severity
protobuf-java has a potential Denial of Service issue
Moderate
CVE-2022-3171
was published
for
com.google.protobuf:protobuf-java
(RubyGems)
Oct 4, 2022
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
High
CVE-2022-2529
was published
for
github.com/cloudflare/goflow/v3
(Go)
Oct 1, 2022
isolated-vm has vulnerable CachedDataOptions in API
Critical
CVE-2022-39266
was published
for
isolated-vm
(npm)
Sep 30, 2022
Improper beacon events in matrix-js-sdk can result in availability issues
Moderate
CVE-2022-39236
was published
for
matrix-js-sdk
(npm)
Sep 29, 2022
Hyperledger Fabric subject to Denial of Service via non-validated request
High
CVE-2022-35253
was published
for
github.com/hyperledger/fabric
(Go)
Sep 25, 2022
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Moderate
CVE-2022-24280
was published
for
org.apache.pulsar:pulsar
(Maven)
Sep 25, 2022
WASM3 Improper Input Validation vulnerability
High
CVE-2022-39974
was published
for
pywasm3
(pip)
Sep 21, 2022
personnummer/dart vulnerable to Improper Input Validation
Low
CVE-2023-22963
was published
for
personnummer
(Pub)
Sep 19, 2022
TensorFlow vulnerable to segfault in `SparseBincount`
Moderate
CVE-2022-35982
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedRelu` and `QuantizedRelu6`
Moderate
CVE-2022-35979
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizeDownAndShrinkRange`
Moderate
CVE-2022-35974
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedMatMul`
Moderate
CVE-2022-35973
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedBiasAdd`
Moderate
CVE-2022-35972
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedInstanceNorm`
Moderate
CVE-2022-35970
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedAdd`
Moderate
CVE-2022-35967
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `QuantizedAvgPool`
Moderate
CVE-2022-35966
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `BlockLSTMGradV2`
Moderate
CVE-2022-35964
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to segfault in `Requantize`
Moderate
CVE-2022-36017
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
Moderate
CVE-2022-36027
was published
for
tensorflow
(pip)
Sep 16, 2022
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
Moderate
CVE-2022-36087
was published
for
oauthlib
(pip)
Sep 16, 2022
ReactPHP's HTTP server parses encoded cookie names so malicious `__Host-` and `__Secure-` cookies can be sent
Moderate
CVE-2022-36032
was published
for
react/http
(Composer)
Sep 16, 2022
mangadex-downloader vulnerable to unauthorized file reading
Moderate
CVE-2022-36082
was published
for
mangadex-downloader
(pip)
Sep 16, 2022
OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functions
High
CVE-2022-36085
was published
for
github.com/open-policy-agent/opa
(Go)
Sep 16, 2022
elrond-go MultiESDTNFTTransfer call on a SC address with missing function name
High
CVE-2022-36058
was published
for
github.com/ElrondNetwork/elrond-go
(Go)
Sep 1, 2022
ProTip!
Advisories are also available from the
GraphQL API