GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,170
Erlang
30
GitHub Actions
19
Go
1,981
Maven
5,000+
npm
3,700
NuGet
656
pip
3,319
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,150 advisories
Filter by severity
cap-std doesn't fully sandbox all the Windows device filenames
Low
CVE-2024-51756
was published
for
cap-async-std
(Rust)
Nov 5, 2024
Wasmtime doesn't fully sandbox all the Windows device filenames
Low
CVE-2024-51745
was published
for
wasmtime
(Rust)
Nov 5, 2024
@workos-inc/authkit-nextjs refresh tokens are logged when the debug flag is enabled
Low
CVE-2024-51752
was published
for
@workos-inc/authkit-nextjs
(npm)
Nov 5, 2024
@workos-inc/authkit-remix refresh tokens are logged when the debug flag is enabled
Low
CVE-2024-51753
was published
for
@workos-inc/authkit-remix
(npm)
Nov 5, 2024
LocalAI Cross-site Scripting vulnerability
Low
CVE-2024-48057
was published
for
github.com/mudler/LocalAI
(Go)
Nov 5, 2024
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
Langchain SQL Injection vulnerability
Low
CVE-2024-8309
was published
for
langchain
(pip)
Oct 29, 2024
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations
Low
CVE-2024-51744
was published
for
github.com/golang-jwt/jwt/v4
(Go)
Nov 4, 2024
Umbraco CMS Cross-site Scripting vulnerability
Low
CVE-2024-10761
was published
for
Umbraco.Cms.Core
(NuGet)
Nov 4, 2024
Grafana org admin can delete pending invites in different org
Low
CVE-2024-10452
was published
for
github.com/grafana/grafana
(Go)
Oct 29, 2024
ASA-2024-005: Potential slashing evasion during re-delegation
Low
GHSA-86h5-xcpx-cfqc
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 27, 2024
Heap OOB read in `tf.raw_ops.Dequantize`
Low
CVE-2021-29582
was published
for
tensorflow
(pip)
May 21, 2021
Segfault in `CTCBeamSearchDecoder`
Low
CVE-2021-29581
was published
for
tensorflow
(pip)
May 21, 2021
Undefined behavior and `CHECK`-fail in `FractionalMaxPoolGrad`
Low
CVE-2021-29580
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `MaxPoolGrad`
Low
CVE-2021-29579
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `FractionalAvgPoolGrad`
Low
CVE-2021-29578
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `AvgPool3DGrad`
Low
CVE-2021-29577
was published
for
tensorflow
(pip)
May 21, 2021
Heap buffer overflow in `MaxPool3DGradGrad`
Low
CVE-2021-29576
was published
for
tensorflow
(pip)
May 21, 2021
Overflow/denial of service in `tf.raw_ops.ReverseSequence`
Low
CVE-2021-29575
was published
for
tensorflow
(pip)
May 21, 2021
Division by 0 in `MaxPoolGradWithArgmax`
Low
CVE-2021-29573
was published
for
tensorflow
(pip)
May 21, 2021
Heap out of bounds read in `MaxPoolGradWithArgmax`
Low
CVE-2021-29570
was published
for
tensorflow
(pip)
May 21, 2021
Heap out of bounds read in `RequantizationRange`
Low
CVE-2021-29569
was published
for
tensorflow
(pip)
May 21, 2021
Reference binding to null in `ParameterizedTruncatedNormal`
Low
CVE-2021-29568
was published
for
tensorflow
(pip)
May 21, 2021
Lack of validation in `SparseDenseCwiseMul`
Low
CVE-2021-29567
was published
for
tensorflow
(pip)
May 21, 2021
Heap OOB access in `Dilation2DBackpropInput`
Low
CVE-2021-29566
was published
for
tensorflow
(pip)
May 21, 2021
ProTip!
Advisories are also available from the
GraphQL API