GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,608
Erlang
33
GitHub Actions
25
Go
2,221
Maven
5,000+
npm
3,893
NuGet
701
pip
3,659
Pub
12
RubyGems
913
Rust
942
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,186 advisories
Filter by severity
Use after free in Neon external buffers
High
GHSA-8mj7-wxmc-f424
was published
for
neon
(Rust)
Jun 17, 2022
Aliased mutable references from `tls_rand` & `TlsWyRand`
Moderate
GHSA-p6gj-gpc8-f8xw
was published
for
nanorand
(Rust)
Jun 17, 2022
AtomicBucket<T> unconditionally implements Send/Sync
Moderate
GHSA-3hxh-7jxm-59x4
was published
for
metrics-util
(Rust)
Jun 17, 2022
Deserialization functions pass uninitialized memory to user-provided Read
High
GHSA-m325-rxjv-pwph
was published
for
messagepack-rs
(Rust)
Jun 17, 2022
XML External Entity Reference in drools
Critical
CVE-2021-41411
was published
for
org.drools:drools-core
(Maven)
Jun 17, 2022
Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags
Moderate
CVE-2021-33295
was published
for
joplin
(npm)
Jun 17, 2022
Insufficiently Protected Credentials in PowerJob
High
CVE-2020-28865
was published
for
com.github.kfcfans:powerjob
(Maven)
Jun 17, 2022
Failure to verify the public key of a `SignedEnvelope` against the `PeerId` in a `PeerRecord`
High
GHSA-wc36-xgcc-jwpr
was published
for
libp2p-core
(Rust)
Jun 17, 2022
Parser creates invalid uninitialized value
High
GHSA-f67m-9j94-qv9j
was published
for
hyper
(Rust)
Jun 16, 2022
Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )
High
GHSA-28p5-7rg4-8v99
was published
for
gfx-auxil
(Rust)
Jun 16, 2022
`Read` on uninitialized buffer may cause UB ( `read_entry()` )
High
GHSA-p56p-gq3f-whg8
was published
for
flumedb
(Rust)
Jun 16, 2022
Generated code can read and write out of bounds in safe code
Critical
GHSA-3jch-9qgp-4844
was published
for
flatbuffers
(Rust)
Jun 16, 2022
enum_map macro can cause UB when `Enum` trait is incorrectly implemented
High
GHSA-rxhx-9fj6-6h2m
was published
for
enum-map
(Rust)
Jun 16, 2022
QueryInterface should call AddRef before returning pointer
Moderate
GHSA-9rg7-3j4f-cf4x
was published
for
derive-com-impl
(Rust)
Jun 16, 2022
Unsoundness in `dashmap` references
High
GHSA-mpg5-fvwp-42m2
was published
for
dashmap
(Rust)
Jun 16, 2022
`Read` on uninitialized memory may cause UB (fn preamble_skipcount())
High
GHSA-r67p-m7g9-gxw6
was published
for
csv-sniffer
(Rust)
Jun 16, 2022
Non-aligned u32 read in Chacha20 encryption and decryption
High
GHSA-pmcv-mgcf-rvxg
was published
for
crypto2
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-8gj8-hv75-gp94
was published
for
crossbeam
(Rust)
Jun 16, 2022
`SegQueue` creates zero value of any type
Moderate
GHSA-6888-wf7j-34jq
was published
for
crossbeam-queue
(Rust)
Jun 16, 2022
Channel creates zero value of any type
High
GHSA-9g55-pg62-m8hh
was published
for
crossbeam-channel
(Rust)
Jun 16, 2022
columnar: `Read` on uninitialized buffer may cause UB (ColumnarReadExt::read_typed_vec())
High
GHSA-cxcc-q839-2cw9
was published
for
columnar
(Rust)
Jun 16, 2022
Potential segfault in `localtime_r` invocations
Moderate
GHSA-cqpr-pcm7-m3jc
was published
for
chrono
(Rust)
Jun 16, 2022
•
withdrawn
InputStream::read_exact : `Read` on uninitialized buffer causes UB
High
GHSA-hmx9-jm3v-33hv
was published
for
buffoon
(Rust)
Jun 16, 2022
ProTip!
Advisories are also available from the
GraphQL API