GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
172 advisories
Filter by severity
GoBase Race Condition vulnerability
Low
CVE-2022-2583
was published
for
github.com/ntbosscher/gobase
(Go)
Dec 28, 2022
Apache Tomcat Race Condition vulnerability
Low
CVE-2021-43980
was published
for
org.apache.tomcat:tomcat
(Maven)
Sep 29, 2022
Talos vulnerable dependency due to race condition in Linux kernel's IP framework XFRM
High
GHSA-34vw-m4rh-r36p
was published
for
github.com/talos-systems/talos
(Go)
Sep 16, 2022
Apache Airflow exposes arbitrary file content
Moderate
CVE-2022-38170
was published
for
apache-airflow
(pip)
Sep 3, 2022
ansible-runner vulnerable to Race Condition
Moderate
CVE-2021-3702
was published
for
ansible-runner
(pip)
Aug 24, 2022
October CMS upload process vulnerable to RCE via Race Condition
High
CVE-2022-24800
was published
for
october/system
(Composer)
Jul 13, 2022
Data race in `Iter` and `IterMut`
High
GHSA-9hpw-r23r-xgm5
was published
for
thread_local
(Rust)
Jun 17, 2022
Uncaught Exception (due to a data race) leads to process termination in Waitress
High
CVE-2022-31015
was published
for
waitress
(pip)
Jun 2, 2022
undertow Race Condition vulnerability
Moderate
CVE-2021-3597
was published
for
io.undertow:undertow-core
(Maven)
May 25, 2022
MutexGuard::map can cause a data race in safe code
Moderate
CVE-2020-35905
was published
for
futures-util
(Rust)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
Moderate
CVE-2019-8232
was published
for
magento/community-edition
(Composer)
May 24, 2022
Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch
Moderate
CVE-2019-7614
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 24, 2022
LXD vulnerable to Race Condition
High
CVE-2015-1340
was published
for
github.com/lxc/lxd
(Go)
May 24, 2022
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib
High
CVE-2010-3494
was published
for
pyftpdlib
(pip)
May 17, 2022
Zope Object Database Denial of Service vulnerability
Moderate
CVE-2010-3495
was published
for
zodb3
(pip)
May 17, 2022
Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
Moderate
CVE-2011-2731
was published
for
org.springframework.security:spring-security-core
(Maven)
May 17, 2022
OpenStack Neutron Race condition vulnerability
Low
CVE-2015-5240
was published
for
neutron
(pip)
May 17, 2022
Apache Guacamole Race Condition vulnerability
High
CVE-2017-3158
was published
for
org.apache.guacamole:guacamole-common
(Maven)
May 14, 2022
Race Condition in Jenkins
High
CVE-2017-1000503
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Phusion Passenger Race Condition Allows Privilege Escalation
High
CVE-2018-12029
was published
for
passenger
(RubyGems)
May 14, 2022
Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat
High
CVE-2016-8745
was published
for
org.apache.tomcat:tomcat-util
(Maven)
May 14, 2022
Radicale is vulnerable to timing oracles and simple bruteforce attacks
High
CVE-2017-8342
was published
for
Radicale
(pip)
May 13, 2022
Smack allows the bypass of TLS protections
Moderate
CVE-2016-10027
was published
for
org.igniterealtime.smack:smack-core
(Maven)
May 13, 2022
OpenStack Neutron Race Condition vulnerability
Moderate
CVE-2017-7543
was published
for
neutron
(pip)
May 13, 2022
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pyftpdlib
Moderate
CVE-2009-5010
was published
for
pyftpdlib
(pip)
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API