GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,395
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,252 advisories
Filter by severity
TensorFlow segfault TFLite converter on per-channel quantized transposed convolutions
Moderate
CVE-2022-36027
was published
for
tensorflow
(pip)
Sep 16, 2022
SFTPGo vulnerable to recovery codes abuse
High
CVE-2022-36071
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Sep 16, 2022
XWiki Cross-Site Request Forgery (CSRF) for actions on tags
Moderate
CVE-2022-36095
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Sep 16, 2022
TensorFlow vulnerable to OOB write in `scatter_nd` in TF Lite
High
CVE-2022-35939
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to OOB read in `Gather_nd` in TF Lite
High
CVE-2022-35937
was published
for
tensorflow
(pip)
Sep 16, 2022
mozjpeg DecompressScanlines::read_scanlines is Unsound
High
GHSA-v8gq-5grq-9728
was published
for
mozjpeg
(Rust)
Sep 16, 2022
ansi_term is Unmaintained
Low
GHSA-74w3-p89x-ffgh
was published
for
ansi_term
(Rust)
Sep 16, 2022
•
withdrawn
Shopware contains sensitive data in backend customer module
Moderate
CVE-2022-36101
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
Moderate
CVE-2022-36087
was published
for
oauthlib
(pip)
Sep 16, 2022
Shopware access control list bypassed via crafted specific URLs
Moderate
CVE-2022-36102
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Moderate
CVE-2022-36109
was published
for
github.com/docker/docker
(Go)
Sep 16, 2022
Go-CVSS has Out-of-bounds Read vulnerability in ParseVector function
High
CVE-2022-39213
was published
for
github.com/pandatix/go-cvss
(Go)
Sep 16, 2022
TensorFlow vulnerable to `CHECK` failure in tf.reshape via overflows
Moderate
CVE-2022-35934
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to `CHECK` failure in `SobolSample` via missing validation
Moderate
CVE-2022-35935
was published
for
tensorflow
(pip)
Sep 16, 2022
Hyperledger indy-node vulnerable to denial of service
High
CVE-2022-31006
was published
for
indy-node
(pip)
Sep 16, 2022
Harbor fails to validate the user permissions when updating a robot account
Moderate
CVE-2022-31667
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when updating tag immutability policies
Moderate
CVE-2022-31669
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when viewing Webhook policies
High
CVE-2022-31666
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when updating tag retention policies
High
CVE-2022-31670
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links
Moderate
CVE-2022-39215
was published
for
tauri
(Rust)
Sep 16, 2022
Poetry Argument Injection can lead to Local Code Execution
High
CVE-2022-36069
was published
for
poetry
(pip)
Sep 16, 2022
TensorFlow vulnerable to `CHECK` fail in `tf.sparse.cross`
Moderate
CVE-2022-35997
was published
for
tensorflow
(pip)
Sep 16, 2022
TensorFlow vulnerable to `CHECK` fail in `Conv2DBackpropInput`
Moderate
CVE-2022-35999
was published
for
tensorflow
(pip)
Sep 16, 2022
Cosign bundle can be crafted to successfully verify a blob even if the embedded rekorBundle does not reference the given signature
Moderate
CVE-2022-36056
was published
for
github.com/sigstore/cosign
(Go)
Sep 16, 2022
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
Moderate
CVE-2022-36020
was published
for
typo3/cms
(Composer)
Sep 16, 2022
ProTip!
Advisories are also available from the
GraphQL API