GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,645 advisories
Filter by severity
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval...
Low
Unreviewed
CVE-2018-20940
was published
May 24, 2022
Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon...
High
Unreviewed
CVE-2019-2345
was published
May 24, 2022
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could...
High
Unreviewed
CVE-2019-11922
was published
May 24, 2022
A race condition is present in the crash generation server used to generate data for the crash...
Moderate
Unreviewed
CVE-2019-9818
was published
May 24, 2022
A race condition occurs while processing perf-event which can lead to a use after free condition...
High
Unreviewed
CVE-2019-2260
was published
May 24, 2022
GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race...
Moderate
Unreviewed
CVE-2018-19572
was published
May 24, 2022
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for...
High
Unreviewed
CVE-2019-13233
was published
May 24, 2022
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename>...
High
Unreviewed
CVE-2019-13226
was published
May 24, 2022
On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition,...
Moderate
Unreviewed
CVE-2019-6627
was published
May 24, 2022
modules/luksbootkeyfile/main.py in Calamares through 3.2.4 has a race condition between the time...
High
Unreviewed
CVE-2019-13178
was published
May 24, 2022
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a...
Moderate
Unreviewed
CVE-2019-5840
was published
May 24, 2022
In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race...
High
Unreviewed
CVE-2019-2008
was published
May 24, 2022
Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing...
High
Unreviewed
CVE-2018-13909
was published
May 24, 2022
Insufficient password protection in the attestation database for Open CIT may allow an...
Low
Unreviewed
CVE-2019-0178
was published
May 24, 2022
In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use...
High
Unreviewed
CVE-2019-2095
was published
May 24, 2022
There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than...
High
Unreviewed
CVE-2019-5216
was published
May 24, 2022
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race...
High
Unreviewed
CVE-2019-12448
was published
May 24, 2022
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict...
Critical
Unreviewed
CVE-2019-12450
was published
May 24, 2022
It was discovered freeradius up to and including version 3.0.19 does not correctly configure...
High
Unreviewed
CVE-2019-10143
was published
May 24, 2022
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote...
High
Unreviewed
CVE-2019-5796
was published
May 24, 2022
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable...
High
Unreviewed
CVE-2018-15664
was published
May 24, 2022
A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and...
Moderate
Unreviewed
CVE-2019-0114
was published
May 24, 2022
An improper authentication vulnerability can be exploited through a race condition that occurs in...
High
Unreviewed
CVE-2019-8978
was published
May 24, 2022
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8....
High
Unreviewed
CVE-2019-11815
was published
May 24, 2022
The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga...
High
Unreviewed
CVE-2019-11675
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API