GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,021 advisories
Filter by severity
Use of Uninitialized Resource in ms3d
High
CVE-2021-26952
was published
for
ms3d
(Rust)
Aug 25, 2021
insert_slice_clone can double drop if Clone panics.
Moderate
CVE-2021-26954
was published
for
qwutils
(Rust)
May 24, 2022
Optional `Deserialize` implementations lacking validation
Moderate
GHSA-jf5h-cf95-w759
was published
for
raw-cpuid
(Rust)
Jun 17, 2022
Window can read out of bounds if Read instance returns more bytes than buffer size
High
GHSA-q579-9wp9-gfp2
was published
for
rdiff
(Rust)
Jun 17, 2022
os_str_bytes relies on undefined behavior of `char::from_u32_unchecked`
High
CVE-2020-35865
was published
for
os_str_bytes
(Rust)
Aug 25, 2021
Improper Certificate Validation in openssl
High
CVE-2016-10931
was published
for
openssl
(Rust)
Aug 25, 2021
Improper type usage in rusqlite
Critical
CVE-2020-35872
was published
for
rusqlite
(Rust)
Aug 25, 2021
Window may read from uninitialized memory locations in rdiff
High
CVE-2021-45694
was published
for
rdiff
(Rust)
Jan 6, 2022
Deserialization of Untrusted Data in rust-cpuid
Critical
CVE-2021-45687
was published
for
raw-cpuid
(Rust)
Jan 6, 2022
Missing Initialization of Resource in pnet
High
CVE-2019-25054
was published
for
pnet
(Rust)
Jan 6, 2022
ProTip!
Advisories are also available from the
GraphQL API