GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,247
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
112 advisories
Filter by severity
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local...
Moderate
Unreviewed
CVE-2022-33716
was published
Aug 6, 2022
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to...
Moderate
Unreviewed
CVE-2022-20119
was published
May 11, 2022
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to...
Moderate
Unreviewed
CVE-2022-20008
was published
May 11, 2022
In camera, there is a possible information disclosure due to uninitialized data. This could lead...
Moderate
Unreviewed
CVE-2022-20096
was published
May 4, 2022
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a...
Moderate
Unreviewed
CVE-2022-34266
was published
Jul 20, 2022
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted...
Moderate
Unreviewed
CVE-2020-35494
was published
May 24, 2022
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to...
Moderate
Unreviewed
CVE-2021-0887
was published
Aug 25, 2022
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to...
Moderate
Unreviewed
CVE-2021-0698
was published
Aug 25, 2022
This vulnerability allows local attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2021-34855
was published
May 24, 2022
In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to...
Moderate
Unreviewed
CVE-2021-0938
was published
May 24, 2022
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user...
Moderate
Unreviewed
CVE-2021-3545
was published
May 24, 2022
This vulnerability allows local attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2021-31417
was published
May 24, 2022
This vulnerability allows local attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2021-31418
was published
May 24, 2022
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2021-21218
was published
May 24, 2022
This vulnerability allows local attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2021-31423
was published
May 24, 2022
This vulnerability allows local attackers to disclose sensitive information on affected...
Moderate
Unreviewed
CVE-2021-31419
was published
May 24, 2022
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data...
Moderate
Unreviewed
CVE-2021-0463
was published
May 24, 2022
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user...
Moderate
Unreviewed
CVE-2020-17482
was published
May 24, 2022
In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to...
Moderate
Unreviewed
CVE-2020-0411
was published
May 24, 2022
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)....
Moderate
Unreviewed
CVE-2020-14703
was published
May 24, 2022
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)....
Moderate
Unreviewed
CVE-2020-14704
was published
May 24, 2022
A vulnerability classified as problematic has been found in Linux Kernel. This affects the...
Moderate
Unreviewed
CVE-2022-3642
was published
Oct 21, 2022
An information disclosure vulnerability exists when Microsoft Office software reads out of bound...
Moderate
Unreviewed
CVE-2020-1342
was published
May 24, 2022
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote...
Moderate
Unreviewed
CVE-2020-13113
was published
May 24, 2022
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim...
Moderate
Unreviewed
CVE-2020-10933
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API