GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,090
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
782 advisories
Filter by severity
Double free in basic_dsp_matrix
High
CVE-2021-25906
was published
for
basic_dsp_matrix
(Rust)
Aug 25, 2021
Read on uninitialized buffer in postscript
High
CVE-2021-26953
was published
for
postscript
(Rust)
Aug 25, 2021
Integer Overflow in openssl-src
Moderate
CVE-2021-23841
was published
for
openssl-src
(Rust)
Aug 25, 2021
Integer Overflow in openssl-src
High
CVE-2021-23840
was published
for
openssl-src
(Rust)
Aug 25, 2021
Incorrect check on buffer length in rand_core
Critical
CVE-2021-27378
was published
for
rand_core
(Rust)
Aug 25, 2021
nb-connect invalidly assumes the memory layout of std::net::SocketAddr
Critical
CVE-2021-27376
was published
for
nb-connect
(Rust)
Aug 25, 2021
quinn invalidly assumes the memory layout of std::net::SocketAddr
High
CVE-2021-28036
was published
for
quinn
(Rust)
Aug 25, 2021
Deserializing an array can free uninitialized memory in byte_struct
Critical
CVE-2021-28033
was published
for
byte_struct
(Rust)
Aug 25, 2021
Use after free in nano_arena
Critical
CVE-2021-28032
was published
for
nano_arena
(Rust)
Aug 25, 2021
Use of Uninitialized Resource in truetype
High
CVE-2021-28030
was published
for
truetype
(Rust)
Aug 25, 2021
Improper synchronization in buttplug
Moderate
CVE-2020-36218
was published
for
buttplug
(Rust)
Aug 25, 2021
Data race in atomic-option
Moderate
CVE-2020-36219
was published
for
atomic-option
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API