GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,025 advisories
Filter by severity
Invalid use of `mem::uninitialized` causes `use-of-uninitialized-value`
Moderate
GHSA-5m39-wx2q-mxg3
was published
for
lzf
(Rust)
Nov 8, 2022
Tauri Filesystem Scope can be Partially Bypassed
Low
CVE-2022-41874
was published
for
Tauri
(Rust)
Nov 8, 2022
ckb type_id script resume may randomly fail
High
GHSA-mcmr-49x3-4jqm
was published
for
ckb
(Rust)
Nov 2, 2022
ckb: Transaction header_deps validation issue (network forking)
Critical
GHSA-7fw6-6mfj-g3q2
was published
for
ckb
(Rust)
Nov 2, 2022
ckb: Large dep group requires a lot of resources to process but the cost to commit the transaction is very low.
Moderate
GHSA-9mfc-chwf-7whf
was published
for
ckb
(Rust)
Nov 2, 2022
X.509 Email Address 4-byte Buffer Overflow
Critical
CVE-2022-3602
was published
for
openssl-src
(Rust)
Nov 1, 2022
X.509 Email Address Variable Length Buffer Overflow
High
CVE-2022-3786
was published
for
openssl-src
(Rust)
Nov 1, 2022
conduit-hyper vulnerable to Denial of Service from unchecked request length
High
CVE-2022-39294
was published
for
conduit-hyper
(Rust)
Oct 31, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
Moderate
CVE-2022-39354
was published
for
evm
(Rust)
Oct 25, 2022
matrix-sdk 0.6.0 logs access tokens
Moderate
GHSA-fc4h-xcf3-qj5f
was published
for
matrix-sdk
(Rust)
Oct 25, 2022
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
High
CVE-2022-3358
was published
for
openssl-src
(Rust)
Oct 11, 2022
Exposure of sensitive Slack webhook URLs in debug logs and traces
High
CVE-2022-39292
was published
for
slack-morphism
(Rust)
Oct 10, 2022
kamadak-exif vulnerable to Infinite loop when parsing PNG files
Moderate
CVE-2021-21235
was published
for
kamadak-exif
(Rust)
Oct 6, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
Moderate
CVE-2022-39252
was published
for
matrix-sdk-crypto
(Rust)
Sep 30, 2022
Weight not properly refunded after EVM execution
Moderate
CVE-2022-39242
was published
for
pallet-ethereum
(Rust)
Sep 23, 2022
personnummer/rust vulnerable to Improper Input Validation
Low
GHSA-28r9-pq4c-wp3c
was published
for
personnummer
(Rust)
Sep 21, 2022
WASM3 Improper Input Validation vulnerability
High
CVE-2022-39974
was published
for
pywasm3
(pip)
Sep 21, 2022
`cell-project` used incorrect variance when projecting through `&Cell<T>`
Moderate
GHSA-p75v-367r-2v23
was published
for
cell-project
(Rust)
Sep 16, 2022
mozjpeg DecompressScanlines::read_scanlines is Unsound
High
GHSA-v8gq-5grq-9728
was published
for
mozjpeg
(Rust)
Sep 16, 2022
ansi_term is Unmaintained
Low
GHSA-74w3-p89x-ffgh
was published
for
ansi_term
(Rust)
Sep 16, 2022
•
withdrawn
Tauri's readDir Endpoint Scope can be Bypassed With Symbolic Links
Moderate
CVE-2022-39215
was published
for
tauri
(Rust)
Sep 16, 2022
linked_list_allocator vulnerable to out-of-bound writes on `Heap` initialization and `Heap::extend`
High
CVE-2022-36086
was published
for
linked_list_allocator
(Rust)
Sep 16, 2022
wee_alloc is Unmaintained
Critical
GHSA-rc23-xxgq-x27g
was published
for
wee_alloc
(Rust)
Sep 16, 2022
traitobject is Unmaintained
Critical
GHSA-pp8r-vv2j-9j5v
was published
for
traitobject
(Rust)
Sep 16, 2022
ProTip!
Advisories are also available from the
GraphQL API