GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,618 advisories
Filter by severity
Header injection possible in Django
Moderate
CVE-2021-32052
was published
for
Django
(pip)
Jun 9, 2021
Insufficient Verification of Data Authenticity in Pillow
Moderate
CVE-2021-28678
was published
for
Pillow
(pip)
Jun 8, 2021
Reflected cross-site scripting issue in Datasette
Moderate
CVE-2021-32670
was published
for
datasette
(pip)
Jun 7, 2021
Insertion of Sensitive Information into Log File in ansible
Moderate
CVE-2021-20191
was published
for
ansible
(pip)
Jun 1, 2021
Improper Verification of Cryptographic Signature in aws-encryption-sdk-cli
Moderate
GHSA-89v2-g37m-g3ff
was published
for
aws-encryption-sdk-cli
(pip)
Jun 1, 2021
Improper Verification of Cryptographic Signature in aws-encryption-sdk
Moderate
GHSA-x5h4-9gqw-942j
was published
for
aws-encryption-sdk
(pip)
Jun 1, 2021
Observable Response Discrepancy in Flask-AppBuilder
Moderate
CVE-2021-29621
was published
for
Flask-AppBuilder
(pip)
May 27, 2021
Interpreter crash from `tf.io.decode_raw`
Moderate
CVE-2021-29614
was published
for
tensorflow
(pip)
May 21, 2021
Incomplete validation in `tf.raw_ops.CTCLoss`
Moderate
CVE-2021-29613
was published
for
tensorflow
(pip)
May 21, 2021
Incomplete validation in `SparseAdd`
Moderate
CVE-2021-29609
was published
for
tensorflow
(pip)
May 21, 2021
Heap OOB and null pointer dereference in `RaggedTensorToTensor`
Moderate
CVE-2021-29608
was published
for
tensorflow
(pip)
May 21, 2021
Integer overflow in TFLite memory allocation
Moderate
CVE-2021-29605
was published
for
tensorflow
(pip)
May 21, 2021
Integer overflow in TFLite concatentation
Moderate
CVE-2021-29601
was published
for
tensorflow
(pip)
May 21, 2021
Null pointer dereference in TFLite's `Reshape` operator
Moderate
CVE-2021-29592
was published
for
tensorflow
(pip)
May 21, 2021
Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint
Moderate
GHSA-7h5v-85w9-pq6c
was published
for
matrix-synapse
(pip)
May 19, 2021
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Moderate
CVE-2021-29510
was published
for
pydantic
(pip)
May 13, 2021
Denial of service attack via push rule patterns in matrix-synapse
Moderate
CVE-2021-29471
was published
for
matrix-synapse
(pip)
May 13, 2021
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Moderate
CVE-2021-21419
was published
for
eventlet
(pip)
May 7, 2021
LinkedIn Oncall vulnerable to Cross-Site Scripting
Moderate
CVE-2021-26722
was published
for
oncall
(pip)
Apr 30, 2021
Uncontrolled Resource Consumption in pillow
Moderate
GHSA-jgpv-4h4c-xhw3
was published
for
pillow
(pip)
Apr 23, 2021
ProTip!
Advisories are also available from the
GraphQL API