GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
121 advisories
Filter by severity
Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied...
High
Unreviewed
CVE-2022-3378
was published
Oct 28, 2022
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X...
High
Unreviewed
CVE-2016-1005
was published
May 17, 2022
Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an...
High
Unreviewed
CVE-2022-34480
was published
Dec 22, 2022
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33...
High
Unreviewed
CVE-2022-39147
was published
Sep 14, 2022
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33...
High
Unreviewed
CVE-2022-39146
was published
Sep 14, 2022
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012...
High
Unreviewed
CVE-2022-27794
was published
May 12, 2022
An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of...
High
Unreviewed
CVE-2018-4001
was published
May 13, 2022
An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in...
High
Unreviewed
CVE-2018-3842
was published
May 13, 2022
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied...
High
Unreviewed
CVE-2022-3377
was published
Nov 16, 2022
Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer...
High
Unreviewed
CVE-2018-1000099
was published
May 13, 2022
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash...
High
Unreviewed
CVE-2018-11803
was published
May 13, 2022
Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in...
High
Unreviewed
CVE-2018-16522
was published
May 13, 2022
Reference binding to nullptr in `MatrixSetDiagV*` ops
High
CVE-2021-37658
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in boosted trees
High
CVE-2021-37662
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in unicode encoding
High
CVE-2021-37667
was published
for
tensorflow
(pip)
Aug 25, 2021
Undefined behavior via `nullptr` reference binding in sparse matrix multiplication
High
CVE-2021-41219
was published
for
tensorflow
(pip)
Nov 10, 2021
Reference binding to `nullptr` in `tf.ragged.cross`
High
CVE-2021-41214
was published
for
tensorflow
(pip)
Nov 10, 2021
Reference binding to nullptr in `MatrixDiagV*` ops
High
CVE-2021-37657
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in `RaggedTensorToVariant`
High
CVE-2021-37666
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in `RaggedTensorToSparse`
High
CVE-2021-37656
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in shape inference
High
CVE-2021-37676
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in map operations
High
CVE-2021-37671
was published
for
tensorflow
(pip)
Aug 25, 2021
Unitialized access in `EinsumHelper::ParseEquation`
High
CVE-2021-41201
was published
for
tensorflow
(pip)
Nov 10, 2021
A remote code execution vulnerability exists in the way that the Windows Graphics Device...
High
Unreviewed
CVE-2019-0853
was published
May 13, 2022
Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an...
High
Unreviewed
CVE-2021-38409
was published
Dec 21, 2021
ProTip!
Advisories are also available from the
GraphQL API