GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
375 advisories
Filter by severity
`net2` invalidly assumes the memory layout of std::net::SocketAddr
Moderate
CVE-2020-35919
was published
for
net2
(Rust)
May 24, 2022
memoffset allows reading uninitialized memory
Moderate
GHSA-wfg4-322g-9vqv
was published
for
memoffset
(Rust)
Jun 21, 2023
Improper `Sync` implementation on `FuturesUnordered` in futures-utils can cause data corruption
Moderate
CVE-2020-35908
was published
for
futures-util
(Rust)
May 24, 2022
cyfs-base vulnerable to misaligned pointer dereference in `ChunkId::new`
Moderate
GHSA-g753-ghr7-q33w
was published
for
cyfs-base
(Rust)
Jun 22, 2023
s2n-quic potential denial of service vulnerability when receiving empty UDP packets
Moderate
GHSA-hxq4-mx37-fqvg
was published
for
s2n-quic
(Rust)
Jun 30, 2023
NULL pointer derefernce in `stb_image`
Moderate
GHSA-ppjr-267j-5p9x
was published
for
stb_image
(Rust)
Mar 20, 2023
impl `FromMdbValue` for bool is unsound
Moderate
GHSA-f9g6-fp84-fv92
was published
for
lmdb-rs
(Rust)
Jul 19, 2023
Cargo extracting malicious crates can fill the file system
Moderate
CVE-2022-36114
was published
for
cargo
(Rust)
Sep 16, 2022
Unsafe parsing in SWHKD
Moderate
CVE-2022-27819
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 8, 2022
mail-internals use-after-free vulnerability in `vec_insert_bytes`
Moderate
GHSA-rcx8-48pc-v9q8
was published
for
mail-internals
(Rust)
Aug 24, 2023
Invalid use of `mem::uninitialized` causes `use-of-uninitialized-value`
Moderate
GHSA-5m39-wx2q-mxg3
was published
for
lzf
(Rust)
Nov 8, 2022
openssl-src NULL pointer Dereference in signature_algorithms processing
Moderate
CVE-2021-3449
was published
for
openssl-src
(Rust)
Aug 25, 2021
Inventory fails to prohibit standard library access prior to initialization of Rust standard library runtime
Moderate
GHSA-ghc8-5cgm-5rpf
was published
for
inventory
(Rust)
Sep 11, 2023
Inventory exposes reference to non-Sync data to an arbitrary thread
Moderate
GHSA-36xm-35qq-795w
was published
for
inventory
(Rust)
Sep 11, 2023
Users vulnerable to unaligned read of `*const *const c_char` pointer
Moderate
GHSA-jcr6-4frq-9gjj
was published
for
users
(Rust)
Sep 11, 2023
Parsing borsh messages with ZST which are not-copy/clone is unsound
Moderate
GHSA-fjx5-qpf4-xjf2
was published
for
borsh
(Rust)
Apr 17, 2023
Sequential calls of encryption API (`encrypt`, `wrap`, and `dump`) result in nonce reuse
Moderate
GHSA-6878-6wc2-pf5h
was published
for
cocoon
(Rust)
Oct 24, 2023
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
Moderate
CVE-2023-34449
was published
for
ink
(Rust)
Jun 14, 2023
Cargo did not verify SSH host keys
Moderate
CVE-2022-46176
was published
for
cargo
(Rust)
Jan 10, 2023
ProTip!
Advisories are also available from the
GraphQL API