GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,083
Erlang
29
GitHub Actions
19
Go
1,909
Maven
5,000+
npm
3,644
NuGet
638
pip
3,260
Pub
10
RubyGems
869
Rust
820
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,121 advisories
Filter by severity
Reference binding to nullptr in `RaggedTensorToVariant`
High
CVE-2021-37666
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in unicode encoding
High
CVE-2021-37667
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in map operations
High
CVE-2021-37671
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr in shape inference
High
CVE-2021-37676
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
High
CVE-2021-37679
was published
for
tensorflow
(pip)
Aug 25, 2021
Null pointer dereference in TFLite
High
CVE-2021-37688
was published
for
tensorflow
(pip)
Aug 25, 2021
Null pointer dereference in TFLite MLIR optimizations
High
CVE-2021-37689
was published
for
tensorflow
(pip)
Aug 25, 2021
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
High
CVE-2021-32797
was published
for
jupyterlab
(pip)
Aug 23, 2021
Remote Code Execution via Script (Python) objects under Python 3
High
CVE-2021-32811
was published
for
Zope
(pip)
Aug 5, 2021
Storage corruption due to variables overwritten by re-entrancy locks
High
GHSA-7f92-rr6w-cq64
was published
for
vyper
(pip)
Aug 5, 2021
XML2Dict XML Entity Expansion Vulnerability
High
CVE-2021-25951
was published
for
XML2Dict
(pip)
Jul 2, 2021
Deserialization of Untrusted Data in Tendenci
High
CVE-2020-14942
was published
for
tendenci
(pip)
Jun 18, 2021
Duplicate Advisory: Reflected cross-site scripting issue in Datasette
High
GHSA-gff3-739c-gxfq
was published
for
datasette
(pip)
Jun 10, 2021
•
withdrawn
Django Access Control Bypass possibly leading to SSRF, RFI, and LFI attacks
High
CVE-2021-33571
was published
for
Django
(pip)
Jun 10, 2021
Cross-Site Request Forgery (CSRF) in FastAPI
High
CVE-2021-32677
was published
for
fastapi
(pip)
Jun 10, 2021
Insufficient Session Expiration in OpenStack Keystone
High
CVE-2020-12690
was published
for
keystone
(pip)
Jun 9, 2021
Uncontrolled Resource Consumption in Pillow
High
CVE-2021-28677
was published
for
Pillow
(pip)
Jun 8, 2021
ProTip!
Advisories are also available from the
GraphQL API