GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
3,714 advisories
Filter by severity
Pillow Out-of-bounds Read vulnerability
High
CVE-2021-25288
was published
for
Pillow
(pip)
Jun 8, 2021
Heap OOB in TFLite's `Gather*` implementations
Moderate
CVE-2021-37687
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in nested `tf.map_fn` with `RaggedTensor`s
High
CVE-2021-37679
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in `SdcaOptimizerV2`
Moderate
CVE-2021-37672
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in `UpperBound` and `LowerBound`
Moderate
CVE-2021-37670
was published
for
tensorflow
(pip)
Aug 25, 2021
Reference binding to nullptr and heap OOB in binary cwise ops
High
CVE-2021-37659
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB in `ResourceScatterUpdate`
High
CVE-2021-37655
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap OOB and CHECK fail in `ResourceGather`
High
CVE-2021-37654
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap buffer overflow in `FractionalAvgPoolGrad`
High
CVE-2021-37651
was published
for
tensorflow
(pip)
Aug 25, 2021
Null pointer dereference and heap OOB read in operations restoring tensors
High
CVE-2021-37639
was published
for
tensorflow
(pip)
Aug 25, 2021
Heap out of bounds access in sparse reduction operations
High
CVE-2021-37635
was published
for
tensorflow
(pip)
Aug 25, 2021
Out of bounds access in compact_arena
Critical
CVE-2019-16139
was published
for
compact_arena
(Rust)
Aug 25, 2021
Out of bounds access in lucet-runtime-internals
Critical
CVE-2020-35859
was published
for
lucet-runtime-internals
(Rust)
Aug 25, 2021
Out of bounds read in simple-slab
Critical
CVE-2020-35892
was published
for
simple-slab
(Rust)
Aug 25, 2021
Out of bounds read in lazy-init
Moderate
CVE-2021-25901
was published
for
lazy-init
(Rust)
Aug 25, 2021
ProTip!
Advisories are also available from the
GraphQL API