GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
213 advisories
Filter by severity
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38749
was published
for
be.cylab:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38750
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38752
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38751
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows...
Moderate
Unreviewed
CVE-2022-1355
was published
Sep 1, 2022
This vulnerability allows local attackers to escalate privileges on affected installations of...
Moderate
Unreviewed
CVE-2022-35867
was published
Aug 4, 2022
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw...
Moderate
Unreviewed
CVE-2022-2078
was published
Jul 1, 2022
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017...
Moderate
Unreviewed
CVE-2021-39845
was published
May 24, 2022
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service ...
Moderate
Unreviewed
CVE-2021-30496
was published
May 24, 2022
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an...
Moderate
Unreviewed
CVE-2019-10974
was published
May 24, 2022
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer...
Moderate
Unreviewed
CVE-2018-10839
was published
May 13, 2022
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd()...
Moderate
Unreviewed
CVE-2018-1071
was published
May 13, 2022
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
Moderate
CVE-2020-5234
was published
for
MessagePack
(NuGet)
Jan 31, 2020
ProTip!
Advisories are also available from the
GraphQL API