GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            13,934 advisories
        Filter by severity
        
      
      
    
                    
                      user/group information can be corrupted across storing in fsimage and reading back from fsimage
                    
                      
  High
                    
                
                      
                        CVE-2018-11768
                      
                      was published
                        for
                        
                          org.apache.hadoop:hadoop-main
                        
                        (Maven)
                      Nov 20, 2019 
                    
                  
                    
                      Denial of service in Netty
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-3488
                      
                      was published
                        for
                        
                          io.netty:netty-handler
                        
                        (Maven)
                      Jun 30, 2020 
                    
                  
                    
                      Improper Restriction of Operations within the Bounds of a Memory Buffer in akka-http-core
                    
                      
  High
                    
                
                      
                        CVE-2017-1000118
                      
                      was published
                        for
                        
                          com.typesafe.akka:akka-http-core_2.11
                        
                        (Maven)
                      Oct 22, 2018 
                    
                  
                    
                      Denial of Service in ethereumjs-vm
                    
                      
  High
                    
                
                      
                        CVE-2018-19183
                      
                      was published
                        for
                        
                          ethereumjs-vm
                        
                        (npm)
                      Nov 21, 2018 
                    
                  
                    
                      Stack Overflow in Apache Mesos
                    
                      
  High
                    
                
                      
                        CVE-2018-11793
                      
                      was published
                        for
                        
                          org.apache.mesos:mesos
                        
                        (Maven)
                      Mar 6, 2019 
                    
                  
                    
                      Uninitialized memory access in outer_cgi
                    
                      
  Critical
                    
                
                      
                        CVE-2021-30454
                      
                      was published
                        for
                        
                          outer_cgi
                        
                        (Rust)
                      Aug 25, 2021 
                    
                  
                    
                      The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3161
                      
                      was published
                      Jan 13, 2023 
                    
                  
                    
                      DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-18439
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-2999
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4235
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4239
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4240
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4246
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4244
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4245
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4242
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-8996
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-0981
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      A vulnerability has been identified in JT2Go (All versions), Solid Edge SE2021 (All versions <...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-44018
                      
                      was published
                      Feb 10, 2022 
                    
                  
                    
                      A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-24322
                      
                      was published
                      Mar 11, 2022 
                    
                  
                    
                      An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-42262
                      
                      was published
                      Mar 13, 2022 
                    
                  
                    
                      In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-39708
                      
                      was published
                      Mar 17, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API