GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4
Moderate
CVE-2023-49798
was published
for
@openzeppelin/contracts
(npm)
Dec 12, 2023
Always incorrect control flow in github.com/mojocn/base64Captcha
Moderate
CVE-2023-45292
was published
for
github.com/mojocn/base64Captcha
(Go)
Dec 12, 2023
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
Moderate
CVE-2023-41338
was published
for
github.com/gofiber/fiber
(Go)
Sep 8, 2023
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
High
CVE-2023-23623
was published
for
electron
(npm)
Sep 6, 2023
Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer
High
CVE-2023-41058
was published
for
parse-server
(npm)
Sep 4, 2023
incorrect order of evaluation of side effects for some builtins
Moderate
CVE-2023-41052
was published
for
vyper
(pip)
Sep 4, 2023
Vyper: reversed order of side effects for some operations
Moderate
CVE-2023-40015
was published
for
vyper
(pip)
Sep 4, 2023
Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update...
High
Unreviewed
CVE-2023-41376
was published
Aug 29, 2023
Insufficient control flow management in the Hyperscan Library maintained by Intel(R) before...
Moderate
Unreviewed
CVE-2023-28711
was published
Aug 11, 2023
Incorrect control flow in Jenkins Gradle Plugin breaks credentials masking in the build log
Moderate
CVE-2023-39152
was published
for
org.jenkins-ci.plugins:gradle
(Maven)
Jul 26, 2023
Vyper's nonpayable default functions are sometimes payable
Moderate
CVE-2023-32675
was published
for
vyper
(pip)
May 22, 2023
Incorrect success value returned in vyper
High
CVE-2023-30629
was published
for
vyper
(pip)
Apr 24, 2023
An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the...
Moderate
Unreviewed
CVE-2022-29609
was published
Apr 20, 2023
An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source...
High
Unreviewed
CVE-2022-29607
was published
Apr 20, 2023
An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of...
High
Unreviewed
CVE-2022-29605
was published
Apr 20, 2023
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
Critical
Unreviewed
CVE-2022-25745
was published
Apr 13, 2023
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will...
High
Unreviewed
CVE-2023-1668
was published
Apr 11, 2023
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper...
High
Unreviewed
CVE-2023-20558
was published
Apr 2, 2023
Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2...
Moderate
Unreviewed
CVE-2022-26841
was published
Feb 16, 2023
Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools...
High
Unreviewed
CVE-2022-27808
was published
Feb 16, 2023
Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before...
High
Unreviewed
CVE-2022-36278
was published
Feb 16, 2023
In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a...
High
Unreviewed
CVE-2023-20915
was published
Jan 26, 2023
In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically...
High
Unreviewed
CVE-2023-20921
was published
Jan 26, 2023
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
Moderate
CVE-2022-41884
was published
for
tensorflow
(pip)
Nov 21, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
Moderate
CVE-2022-39354
was published
for
evm
(Rust)
Oct 25, 2022
ProTip!
Advisories are also available from the
GraphQL API