GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,176
Erlang
30
GitHub Actions
19
Go
1,982
Maven
5,000+
npm
3,701
NuGet
656
pip
3,323
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,212 advisories
Filter by severity
langflow has vulnerability in PythonCodeTool component
High
CVE-2024-42835
was published
for
langflow
(pip)
Oct 31, 2024
Stack overflow due to looping TFLite subgraph
High
CVE-2021-29591
was published
for
tensorflow
(pip)
May 21, 2021
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
CVE-2024-46977
was published
for
openc3
(RubyGems)
Oct 2, 2024
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
High
CVE-2024-32498
was published
for
cinder
(pip)
Jul 5, 2024
ebookmeta XML External Entity vulnerability
High
CVE-2024-37388
was published
for
ebookmeta
(pip)
Jun 7, 2024
TensorFlow vulnerable to heap out of bounds read in filesystem glob matching
High
CVE-2020-26269
was published
for
tensorflow
(pip)
Oct 7, 2022
Segfault in `tf.quantization.quantize_and_dequantize`
High
CVE-2020-15265
was published
for
tensorflow
(pip)
Nov 13, 2020
Data corruption in tensorflow-lite
High
CVE-2020-15208
was published
for
tensorflow
(pip)
Sep 25, 2020
Waitress vulnerable to DoS leading to high CPU usage/resource exhaustion
High
CVE-2024-49769
was published
for
waitress
(pip)
Oct 29, 2024
Duplicate Advisory: pyload-ng vulnerable to RCE with js2py sandbox escape
High
GHSA-25pw-q952-x37g
was published
for
pyload-ng
(pip)
Oct 28, 2024
•
withdrawn
Integer truncation in Shard API usage
High
CVE-2020-15202
was published
for
tensorflow
(pip)
Sep 25, 2020
MultipartParser denial of service with too many fields or files
High
CVE-2023-30798
was published
for
starlette
(pip)
Feb 14, 2023
Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files
High
GHSA-3qj8-93xh-pwh2
was published
for
starlette
(pip)
Apr 21, 2023
•
withdrawn
Segmentation fault in tensorflow-lite
High
CVE-2020-15210
was published
for
tensorflow
(pip)
Sep 25, 2020
Null pointer dereference in tensorflow-lite
High
CVE-2020-15209
was published
for
tensorflow
(pip)
Sep 25, 2020
OISF suricata-update unsafely deserializes YAML data
High
CVE-2018-1000167
was published
for
suricata-update
(pip)
May 14, 2022
Denial of service vulnerability when parsing multipart request body
High
CVE-2023-25578
was published
for
starlite
(pip)
Feb 15, 2023
ProTip!
Advisories are also available from the
GraphQL API