GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
98 advisories
Filter by severity
Excessive Iteration in Compress
High
CVE-2021-35515
was published
for
org.apache.commons:commons-compress
(Maven)
Aug 2, 2021
Infinite Loop in Apache PDFBox
Moderate
CVE-2021-31812
was published
for
org.apache.pdfbox:pdfbox
(Maven)
Jun 15, 2021
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1...
Moderate
Unreviewed
CVE-2019-12973
was published
May 24, 2022
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping...
High
Unreviewed
CVE-2021-4021
was published
Feb 25, 2022
In the Accounts package, there is a possible crash due to improper input validation. This could...
Moderate
Unreviewed
CVE-2019-9376
was published
May 24, 2022
Using the Location API in a loop could have caused severe application hangs and crashes. This...
Moderate
Unreviewed
CVE-2021-43545
was published
Dec 9, 2021
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and...
Moderate
Unreviewed
CVE-2020-14303
was published
May 24, 2022
An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU"...
Moderate
Unreviewed
CVE-2021-28950
was published
May 24, 2022
In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386...
High
Unreviewed
CVE-2021-3128
was published
May 24, 2022
In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive...
High
Unreviewed
CVE-2021-23270
was published
May 24, 2022
In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL...
High
Unreviewed
CVE-2021-3125
was published
May 24, 2022
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows...
High
Unreviewed
CVE-2021-39924
was published
Nov 20, 2021
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability....
Moderate
Unreviewed
CVE-2021-21565
was published
May 24, 2022
In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e.,...
Moderate
Unreviewed
CVE-2019-9547
was published
May 13, 2022
In libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, a DoS in mxf_read_index_entry_array() due to lack...
High
Unreviewed
CVE-2017-14170
was published
May 13, 2022
In libavformat/nsvdec.c in FFmpeg 2.4 and 3.3.3, a DoS in nsv_parse_NSVf_header() due to lack of...
High
Unreviewed
CVE-2017-14171
was published
May 13, 2022
Excessive Iteration Denial of Service in Apache PDFBox
Moderate
CVE-2021-27807
was published
for
org.apache.pdfbox:pdfbox
(Maven)
Jun 16, 2021
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long...
Moderate
Unreviewed
CVE-2018-11507
was published
May 13, 2022
Excessive CPU usage
High
CVE-2021-39204
was published
for
github.com/pomerium/pomerium
(Go)
Sep 10, 2021
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop...
High
Unreviewed
CVE-2018-7323
was published
May 13, 2022
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of...
High
Unreviewed
CVE-2021-39923
was published
Nov 20, 2021
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop...
High
Unreviewed
CVE-2018-7321
was published
May 13, 2022
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage...
Moderate
Unreviewed
CVE-2018-9133
was published
May 13, 2022
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
High
Unreviewed
CVE-2018-11813
was published
May 13, 2022
In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector...
High
Unreviewed
CVE-2018-14342
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API