GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,311 advisories
Filter by severity
An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the...
Moderate
Unreviewed
CVE-2022-41845
was published
Oct 1, 2022
rdiffweb's lack of token name length limit can result in DoS or memory corruption
High
CVE-2022-3371
was published
for
rdiffweb
(pip)
Oct 1, 2022
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0...
Critical
Unreviewed
CVE-2022-29503
was published
Sep 30, 2022
rdiffweb's unlimited length Fullname field can lead to DoS
Moderate
CVE-2022-3364
was published
for
rdiffweb
(pip)
Sep 30, 2022
rdiffweb allows unlimited length of root directory name, which could result in DoS
High
CVE-2022-3295
was published
for
rdiffweb
(pip)
Sep 27, 2022
rdiffweb vulnerable to potential DoS via memory consumption
High
CVE-2022-3298
was published
for
rdiffweb
(pip)
Sep 27, 2022
SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor...
Moderate
Unreviewed
CVE-2022-35089
was published
Sep 22, 2022
Apache Kafka vulnerability can lead to brokers hitting OutOfMemoryException, causing Denial of Service
High
CVE-2022-34917
was published
for
org.apache.kafka:kafka
(Maven)
Sep 21, 2022
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung...
High
Unreviewed
CVE-2022-40762
was published
Sep 17, 2022
Helm Controller denial of service
High
CVE-2022-36049
was published
for
github.com/fluxcd/flux2
(Go)
Sep 16, 2022
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling
Moderate
CVE-2022-36104
was published
for
typo3/cms
(Composer)
Sep 16, 2022
Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)
High
CVE-2022-25897
was published
for
org.eclipse.milo:sdk-server
(Maven)
Sep 15, 2022
axum-core has no default limit put on request bodies
High
CVE-2022-3212
was published
for
axum-core
(Rust)
Sep 15, 2022
Duplicate of GHSA-m77f-652q-wwp4
High
GHSA-2gg5-7c4v-6xx2
was published
for
axum-core
(Rust)
Sep 15, 2022
•
withdrawn
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of...
Moderate
Unreviewed
CVE-2022-3147
was published
Sep 10, 2022
In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function ...
Moderate
Unreviewed
CVE-2020-35534
was published
Sep 2, 2022
A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with...
Moderate
Unreviewed
CVE-2022-1325
was published
Sep 1, 2022
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however,...
Moderate
Unreviewed
CVE-2022-38153
was published
Sep 1, 2022
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/addRouting.
High
Unreviewed
CVE-2022-36620
was published
Sep 1, 2022
Helm Vulnerable to denial of service through string value parsing
Moderate
CVE-2022-36055
was published
for
helm.sh/helm/v3
(Go)
Aug 30, 2022
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can...
Moderate
Unreviewed
CVE-2022-0480
was published
Aug 29, 2022
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with...
Moderate
Unreviewed
CVE-2021-3669
was published
Aug 27, 2022
XNIO `notifyReadClosed` method logging message to unexpected end
High
CVE-2022-0084
was published
for
org.jboss.xnio:xnio-all
(Maven)
Aug 27, 2022
All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a...
High
Unreviewed
CVE-2022-24381
was published
Aug 24, 2022
All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when...
High
Unreviewed
CVE-2022-24298
was published
Aug 24, 2022
ProTip!
Advisories are also available from the
GraphQL API