GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Pillow Buffer overflow in ImagingLibTiffDecode
Moderate
CVE-2016-0740
was published
for
Pillow
(pip)
Jul 24, 2018
Pillow buffer overflow in ImagingPcdDecode
Moderate
CVE-2016-2533
was published
for
Pillow
(pip)
Jul 24, 2018
Pillow Buffer overflow in ImagingFliDecode
Moderate
CVE-2016-0775
was published
for
Pillow
(pip)
Jul 24, 2018
Heap Overflow in PyMiniRacer
Moderate
CVE-2020-25489
was published
for
py-mini-racer
(pip)
Sep 18, 2020
Heap buffer overflow in Tensorflow
Moderate
CVE-2020-15198
was published
for
tensorflow
(pip)
Sep 25, 2020
Denial of service in tensorflow-lite
Moderate
CVE-2020-15213
was published
for
tensorflow
(pip)
Sep 25, 2020
Improper Restriction of Operations within the Bounds of a Memory Buffer in OpenCV
Moderate
CVE-2017-17760
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
Moderate
CVE-2013-0270
was published
for
keystone
(pip)
May 5, 2022
PyFriBidi Buffer overflow in the fribidi_utf8_to_unicode function
Moderate
CVE-2012-1176
was published
for
pyfribidi
(pip)
May 17, 2022
Pillow Buffer overflow in Jpeg2KEncode.c
Moderate
CVE-2016-3076
was published
for
pillow
(pip)
May 17, 2022
OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack
Moderate
CVE-2013-4179
was published
for
nova
(pip)
May 17, 2022
OpenStack Swift allows authenticated users to cause a denial of service
Moderate
CVE-2013-4155
was published
for
swift
(pip)
May 17, 2022
Improper Restriction of Operations within the Bounds of a Memory Buffer in python-cjson
Moderate
CVE-2010-1666
was published
for
python-cjson
(pip)
May 17, 2022
Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow
Moderate
CVE-2023-27506
was published
for
intel-tensorflow
(pip)
Aug 11, 2023
ProTip!
Advisories are also available from the
GraphQL API