GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,350 advisories
Filter by severity
XML External Entity Reference in drools
Critical
CVE-2021-41411
was published
for
org.drools:drools-core
(Maven)
Jun 17, 2022
Insufficiently Protected Credentials in PowerJob
High
CVE-2020-28865
was published
for
com.github.kfcfans:powerjob
(Maven)
Jun 17, 2022
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags
Moderate
CVE-2021-33295
was published
for
joplin
(npm)
Jun 17, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`
High
GHSA-wc36-xgcc-jwpr
was published
for
libp2p-core
(Rust)
Jun 17, 2022
Parser creates invalid uninitialized value
High
GHSA-f67m-9j94-qv9j
was published
for
hyper
(Rust)
Jun 16, 2022
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )
High
GHSA-28p5-7rg4-8v99
was published
for
gfx-auxil
(Rust)
Jun 16, 2022
`Read` on uninitialized buffer may cause UB ( `read_entry()` )
High
GHSA-p56p-gq3f-whg8
was published
for
flumedb
(Rust)
Jun 16, 2022
Generated code can read and write out of bounds in safe code
Critical
GHSA-3jch-9qgp-4844
was published
for
flatbuffers
(Rust)
Jun 16, 2022
enum_map macro can cause UB when `Enum` trait is incorrectly implemented
High
GHSA-rxhx-9fj6-6h2m
was published
for
enum-map
(Rust)
Jun 16, 2022
QueryInterface should call AddRef before returning pointer
Moderate
GHSA-9rg7-3j4f-cf4x
was published
for
derive-com-impl
(Rust)
Jun 16, 2022
Unsoundness in `dashmap` references
High
GHSA-mpg5-fvwp-42m2
was published
for
dashmap
(Rust)
Jun 16, 2022
`Read` on uninitialized memory may cause UB (fn preamble_skipcount())
High
GHSA-r67p-m7g9-gxw6
was published
for
csv-sniffer
(Rust)
Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption
High
GHSA-pmcv-mgcf-rvxg
was published
for
crypto2
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-8gj8-hv75-gp94
was published
for
crossbeam
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-6888-wf7j-34jq
was published
for
crossbeam-queue
(Rust)
Jun 16, 2022
Channel creates zero value of any type
High
GHSA-9g55-pg62-m8hh
was published
for
crossbeam-channel
(Rust)
Jun 16, 2022
columnar: `Read` on uninitialized buffer may cause UB (ColumnarReadExt::read_typed_vec())
High
GHSA-cxcc-q839-2cw9
was published
for
columnar
(Rust)
Jun 16, 2022
Potential segfault in `localtime_r` invocations
Moderate
GHSA-cqpr-pcm7-m3jc
was published
for
chrono
(Rust)
Jun 16, 2022
•
withdrawn
InputStream::read_exact : `Read` on uninitialized buffer causes UB
High
GHSA-hmx9-jm3v-33hv
was published
for
buffoon
(Rust)
Jun 16, 2022
`Read` on uninitialized buffer can cause UB (impl of `ReadKVExt`)
High
GHSA-5phc-849h-vcxg
was published
for
bronzedb-protocol
(Rust)
Jun 16, 2022
`read` on uninitialized buffer may cause UB (bite::read::BiteReadExpandedExt::read_framed_max)
High
GHSA-72r2-rg28-47v9
was published
for
bite
(Rust)
Jun 16, 2022
'Read' on uninitialized memory may cause UB
High
GHSA-c6px-4grw-hrjr
was published
for
binjs_io
(Rust)
Jun 16, 2022
Arrow2 allows double free in `safe` code
High
GHSA-5j8w-r7g8-5472
was published
for
arrow2
(Rust)
Jun 16, 2022
`FixedSizeBinaryArray` does not perform bound checks on accessing values and offsets
High
GHSA-qgrp-8f3v-q85p
was published
for
arrow
(Rust)
Jun 16, 2022
ProTip!
Advisories are also available from the
GraphQL API