GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,025 advisories
Filter by severity
Allocation of Resources Without Limits or Throttling in ckb
High
CVE-2021-45699
was published
for
ckb
(Rust)
Jan 6, 2022
Use of Uninitialized Resource in tectonic_xdv
Critical
CVE-2021-45703
was published
for
tectonic_xdv
(Rust)
Jan 6, 2022
Use After Free in tremor-script
High
CVE-2021-45702
was published
for
tremor-script
(Rust)
Jan 6, 2022
Pointer dereference in nanorand
Critical
CVE-2021-45705
was published
for
nanorand
(Rust)
Jan 6, 2022
Out-of-bounds Write and Race Condition in metrics-util
High
CVE-2021-45704
was published
for
metrics-util
(Rust)
Jan 6, 2022
Memory flaw in zeroize_derive
Critical
CVE-2021-45706
was published
for
zeroize_derive
(Rust)
Jan 6, 2022
Abomonation transmutes &T to and from &[u8] without sufficient constraints
High
CVE-2021-45708
was published
for
abomonation
(Rust)
Jan 6, 2022
Uncontrolled Resource Consumption in simple_asn1
High
CVE-2021-45711
was published
for
simple_asn1
(Rust)
Jan 6, 2022
Use of a Broken or Risky Cryptographic Algorithm in crypto2
Critical
CVE-2021-45709
was published
for
crypto2
(Rust)
Jan 6, 2022
DoS Vulnerability from Upstream Actix Web Issues
High
GHSA-gjrj-9rj4-pgwx
was published
for
perseus-actix-web
(Rust)
Dec 15, 2021
Invalid handling of `X509_verify_cert()` internal errors in libssl
High
CVE-2021-4044
was published
for
openssl-src
(Rust)
Dec 15, 2021
Improper Input Validation in fruity
High
CVE-2021-43620
was published
for
fruity
(Rust)
Nov 16, 2021
Memory exhaustion in routinator
High
CVE-2021-43174
was published
for
routinator
(Rust)
Nov 11, 2021
coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
Moderate
CVE-2021-3917
was published
for
coreos-installer
(Rust)
Nov 8, 2021
ProTip!
Advisories are also available from the
GraphQL API