GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,732
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,952
Pub
13
RubyGems
1,055
Rust
1,343
Swift
54
Unreviewed advisories
All unreviewed
5,000+
416 advisories
Filter by severity
Untrusted data can lead to DoS attack due to hash collisions and stack overflow in MessagePack
Moderate
CVE-2020-5234
was published
for
MessagePack
(NuGet)
Jan 31, 2020
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd()...
Moderate
Unreviewed
CVE-2018-1071
was published
May 13, 2022
A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX...
Moderate
Unreviewed
CVE-2017-7936
was published
May 13, 2022
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A...
Moderate
Unreviewed
CVE-2017-12732
was published
May 13, 2022
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer...
Moderate
Unreviewed
CVE-2018-10839
was published
May 13, 2022
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8...
Moderate
Unreviewed
CVE-2017-14016
was published
May 17, 2022
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server ...
Moderate
Unreviewed
CVE-2014-0774
was published
May 17, 2022
Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow...
Moderate
Unreviewed
CVE-2014-5407
was published
May 17, 2022
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an...
Moderate
Unreviewed
CVE-2019-10974
was published
May 24, 2022
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service ...
Moderate
Unreviewed
CVE-2021-30496
was published
May 24, 2022
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017...
Moderate
Unreviewed
CVE-2021-39845
was published
May 24, 2022
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw...
Moderate
Unreviewed
CVE-2022-2078
was published
Jul 1, 2022
This vulnerability allows local attackers to escalate privileges on affected installations of...
Moderate
Unreviewed
CVE-2022-35867
was published
Aug 4, 2022
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows...
Moderate
Unreviewed
CVE-2022-1355
was published
Sep 1, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38751
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38752
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38750
was published
for
org.yaml:snakeyaml
(Maven)
Sep 6, 2022
snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write
Moderate
CVE-2022-38749
was published
for
be.cylab:snakeyaml
(Maven)
Sep 6, 2022
Denial of Service due to parser crash
Moderate
CVE-2022-40152
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
Jettison parser crash by stackoverflow
Moderate
CVE-2022-40149
was published
for
org.codehaus.jettison:jettison
(Maven)
Sep 17, 2022
In face detect driver, there is a possible out of bounds write due to a missing bounds check....
Moderate
Unreviewed
CVE-2022-38672
was published
Oct 15, 2022
Snakeyaml vulnerable to Stack overflow leading to denial of service
Moderate
CVE-2022-41854
was published
for
org.yaml:snakeyaml
(Maven)
Nov 11, 2022
XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf...
Moderate
Unreviewed
CVE-2022-43295
was published
Nov 15, 2022
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This...
Moderate
Unreviewed
CVE-2022-39106
was published
Dec 6, 2022
In face detect driver, there is a possible out of bounds write due to a missing bounds check....
Moderate
Unreviewed
CVE-2022-39129
was published
Dec 6, 2022
ProTip!
Advisories are also available from the
GraphQL API