- CVE-2020-8560 (to be disclosed; $200 bounty)
 - CVE-2020-8556 (to be disclosed; $1000 bounty)
 
- out-of-range panic in strconv.go:269
 
- Buffer overflow when continuously send SIGHUP to postgres
 
- CVE-2018-11813 (with acknowledgement in official website)
 
- Assertion Failure in ucl_msgpack.c:845
 
- CVE-2018-11212
 - CVE-2018-11213
 - CVE-2018-11214
 
- CVE-2018-11536
 - Heap buffer overflow in md_process_inlines()
 
- CVE-2018-11547
 - CVE-2018-11546
 - CVE-2018-11545
 
- SEGV in TextUtils.cpp:157
 
- CVE-2018-11363
 
- CVE-2018-11364
 
- CVE-2018-12064
 
- CVE-2018-12093
 - CVE-2018-12092
 
- CVE-2018-12504
 - CVE-2018-12503
 
- CVE-2018-12688
 - CVE-2018-12687
 
- SIGSEGV in frame.rs:153
 
- Infinite loop in miniz_tester.cpp:652
 
- CVE-2018-20652 (duplicated)
 - CVE-2018-12503 (duplicated)
 - CVE-2020-18430
 - CVE-2020-18428
 
- Undefined behavior in config_setting_set_string (libconfig.c:1178)
 - Undefined behavior in __config_name_compare (libconfig.c:134)