GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end...
Moderate
Unreviewed
CVE-2021-42715
was published
May 24, 2022
In setEnabledSetting of PackageManager.java, there is a possible way to get the device into an...
Moderate
Unreviewed
CVE-2022-20476
was published
Dec 13, 2022
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of...
Moderate
Unreviewed
CVE-2005-2224
was published
May 1, 2022
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers...
Moderate
Unreviewed
CVE-2005-0851
was published
May 1, 2022
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a...
Moderate
Unreviewed
CVE-2015-5239
was published
May 24, 2022
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing...
Moderate
Unreviewed
CVE-2020-27618
was published
May 24, 2022
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the...
Moderate
Unreviewed
CVE-2018-5786
was published
Apr 30, 2022
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W...
Moderate
Unreviewed
CVE-2020-23566
was published
May 24, 2022
In an MPLS P2MP environment a Loop with Unreachable Exit Condition vulnerability in the routing...
Moderate
Unreviewed
CVE-2021-31363
was published
May 24, 2022
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS...
Moderate
Unreviewed
CVE-2021-29365
was published
May 24, 2022
An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send...
Moderate
Unreviewed
CVE-2021-42084
was published
May 24, 2022
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14...
Moderate
Unreviewed
CVE-2021-3679
was published
May 24, 2022
A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive...
Moderate
Unreviewed
CVE-2021-33599
was published
May 24, 2022
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization ...
Moderate
Unreviewed
CVE-2021-34332
was published
May 24, 2022
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the...
Moderate
Unreviewed
CVE-2020-18442
was published
May 24, 2022
Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An...
Moderate
Unreviewed
CVE-2020-9307
was published
May 24, 2022
In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured...
Moderate
Unreviewed
CVE-2021-0221
was published
May 24, 2022
A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in...
Moderate
Unreviewed
CVE-2021-3508
was published
May 24, 2022
wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the...
Moderate
Unreviewed
CVE-2021-44718
was published
Sep 3, 2022
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a...
Moderate
Unreviewed
CVE-2020-36310
was published
May 24, 2022
A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with...
Moderate
Unreviewed
CVE-2021-25673
was published
May 24, 2022
Modem will enter into busy mode in an infinite loop while parsing histogram dimension due to...
Moderate
Unreviewed
CVE-2020-11186
was published
May 24, 2022
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw...
Moderate
Unreviewed
CVE-2020-29385
was published
May 24, 2022
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among...
Moderate
Unreviewed
CVE-2020-16127
was published
May 24, 2022
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel...
Moderate
Unreviewed
CVE-2020-27152
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API