GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
webp crate may expose memory contents when encoding an image
Moderate
GHSA-9q78-27f3-2jmh
was published
for
webp
(Rust)
Aug 29, 2025
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
Moderate
CVE-2025-48072
was published
for
OpenEXR
(pip)
Jul 31, 2025
OpenZeppelin Contracts Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
Moderate
CVE-2025-54070
was published
for
@openzeppelin/contracts
(npm)
Jul 17, 2025
Wasmtime out of bounds read/write with zero-memory-pages configuration
Moderate
CVE-2022-39392
was published
for
wasmtime
(Rust)
Nov 10, 2022
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
Moderate
GHSA-9cc5-2pq7-hfj8
was published
for
xmas-elf
(Rust)
Mar 26, 2025
Onnx Out-of-bounds Read vulnerability
Moderate
CVE-2024-27319
was published
for
onnx
(pip)
Feb 23, 2024
Browsershot Improper Input Validation vulnerability
Moderate
CVE-2024-21549
was published
for
spatie/browsershot
(Composer)
Dec 20, 2024
Denial of service in geth
Moderate
CVE-2020-26242
was published
for
github.com/ethereum/go-ethereum
(Go)
Jun 29, 2021
Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
Moderate
CVE-2024-29857
was published
for
BouncyCastle
(Maven)
May 14, 2024
`ruzstd` uninit and out-of-bounds memory reads
Moderate
GHSA-x3f4-45xf-rjm7
was published
for
ruzstd
(Rust)
Dec 2, 2024
PaddlePaddle segfault in paddle.mode
Moderate
CVE-2023-38678
was published
for
PaddlePaddle
(pip)
Jan 3, 2024
Open Chinese Convert subject to Denial of Service via Out-of-bounds Read
Moderate
CVE-2018-16982
was published
for
opencc
(npm)
May 14, 2022
Capstone SEGV caused by a read memory access
Moderate
CVE-2016-7151
was published
for
capstone
(pip)
May 24, 2022
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Moderate
CVE-2021-39218
was published
for
wasmtime
(pip)
Sep 20, 2021
wasm3 uncontrolled memory allocation vulnerability
Moderate
CVE-2024-27529
was published
for
github.com/shareup/wasm-interpreter-apple
(pip)
Nov 9, 2024
Arbitrary memory read in `ImmutableConst`
Moderate
CVE-2021-41227
was published
for
tensorflow
(pip)
Nov 10, 2021
Heap OOB in `SparseBinCount`
Moderate
CVE-2021-41226
was published
for
tensorflow
(pip)
Nov 10, 2021
`SparseFillEmptyRows` heap OOB
Moderate
CVE-2021-41224
was published
for
tensorflow
(pip)
Nov 10, 2021
Heap OOB in `FusedBatchNorm` kernels
Moderate
CVE-2021-41223
was published
for
tensorflow
(pip)
Nov 10, 2021
Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops
Moderate
CVE-2021-41205
was published
for
tensorflow
(pip)
Nov 10, 2021
Heap OOB in TFLite's `Gather*` implementations
Moderate
CVE-2021-37687
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in `SdcaOptimizerV2`
Moderate
CVE-2021-37672
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in `UpperBound` and `LowerBound`
Moderate
CVE-2021-37670
was published
for
tensorflow
(pip)
Aug 25, 2021
Incomplete validation in `tf.raw_ops.CTCLoss`
Moderate
CVE-2021-29613
was published
for
tensorflow
(pip)
May 21, 2021
ProTip!
Advisories are also available from the
GraphQL API