GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,218
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,332
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior...
Moderate
Unreviewed
CVE-2021-25525
was published
Dec 9, 2021
Authz Module Non-Determinism
Moderate
CVE-2021-41135
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Oct 21, 2021
Denial of Service (DoS) in mongo-express
Moderate
CVE-2021-23372
was published
for
mongo-express
(npm)
Oct 6, 2021
Incorrect handling of H2 GOAWAY + SETTINGS frames
High
CVE-2021-39162
was published
for
github.com/pomerium/pomerium
(Go)
Sep 10, 2021
Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20
Moderate
CVE-2021-33605
was published
for
com.vaadin:vaadin-checkbox-flow
(Maven)
Aug 30, 2021
Improper Check for Unusual or Exceptional Conditions in json-smart
Moderate
CVE-2021-27568
was published
for
net.minidev:json-smart
(Maven)
Jun 16, 2021
Ory fosite contains Improper Handling of Exceptional Conditions
High
CVE-2020-15223
was published
for
github.com/ory/fosite
(Go)
May 24, 2021
CHECK-fail in `QuantizeAndDequantizeV4Grad`
Low
CVE-2021-29544
was published
for
tensorflow
(pip)
May 21, 2021
CHECK-fail in tf.raw_ops.EncodePng
Low
CVE-2021-29531
was published
for
tensorflow
(pip)
May 21, 2021
Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11
Low
CVE-2018-25007
was published
for
com.vaadin:flow-server
(Maven)
Apr 19, 2021
Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11
Low
GHSA-3h5r-928v-mxhh
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Integer truncation in Shard API usage
High
CVE-2020-15202
was published
for
tensorflow
(pip)
Sep 25, 2020
Potential buffer overflow in psd-tools
Critical
CVE-2020-10571
was published
for
psd-tools
(pip)
Mar 16, 2020
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
Low
CVE-2020-5215
was published
for
tensorflow
(pip)
Jan 28, 2020
Improper Check for Unusual or Exceptional Conditions in Connect2id Nimbus JOSE+JWT
Critical
CVE-2019-17195
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Oct 16, 2019
ProTip!
Advisories are also available from the
GraphQL API