GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,318 advisories
Filter by severity
TensorFlow has Null Pointer Error in LookupTableImportV2
High
CVE-2023-25672
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Floating Point Exception in TensorListSplit with XLA
High
CVE-2023-25673
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
High
CVE-2023-25669
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
High
CVE-2023-25670
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
High
CVE-2023-25674
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Floating Point Exception in TFLite in conv kernel
High
CVE-2023-27579
was published
for
tensorflow
(pip)
Mar 24, 2023
Signature verification vulnerability in Stark Bank ecdsa libraries
High
GHSA-9wx7-jrvc-28mm
was published
for
com.starkbank:ecdsa-java
(Maven)
Nov 8, 2021
TensorFlow has segmentation fault in tfg-translate
High
CVE-2023-25671
was published
for
tensorflow
(pip)
Mar 24, 2023
TensorFlow has Segfault in Bincount with XLA
High
CVE-2023-25675
was published
for
tensorflow
(pip)
Mar 24, 2023
Kiwi TCMS Stored Cross-site Scripting via SVG file
High
CVE-2023-27489
was published
for
kiwitcms
(pip)
Mar 30, 2023
Uncontrolled Resource Consumption in asyncua and opcua
High
CVE-2022-25304
was published
for
asyncua
(pip)
Aug 24, 2022
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
High
CVE-2022-41894
was published
for
tensorflow
(pip)
Nov 21, 2022
Remote code execution in Apache Airflow Docker's Provider
High
CVE-2022-38362
was published
for
apache-airflow-providers-docker
(pip)
Aug 17, 2022
OS Command Injection in Apache Airflow
High
CVE-2022-41131
was published
for
apache-airflow-providers-apache-hive
(pip)
Nov 22, 2022
Apache Airflow Spark Provider vulnerable to improper input validation
High
CVE-2023-28710
was published
for
apache-airflow-providers-apache-spark
(pip)
Apr 7, 2023
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
High
CVE-2023-29005
was published
for
Flask-AppBuilder
(pip)
Apr 10, 2023
Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui
High
GHSA-v988-828w-xvf2
was published
for
rucio-webui
(pip)
Oct 22, 2021
Out-of-bounds Write in OpenCV
High
CVE-2019-5064
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
Weak Password Requirements in calibreweb
High
CVE-2023-2106
was published
for
calibreweb
(pip)
Apr 15, 2023
TensorFlow has double free in Fractional(Max/Avg)Pool
High
CVE-2023-25801
was published
for
tensorflow
(pip)
Mar 24, 2023
pgadmin4 vulnerable to Code Injection
High
CVE-2022-4223
was published
for
pgadmin4
(pip)
Dec 13, 2022
Improper Control of Generation of Code ('Code Injection') in Azure CLI
High
CVE-2022-39327
was published
for
azure-cli
(pip)
Oct 25, 2022
Uncontrolled Resource Consumption in Apache DolphinScheduler
High
CVE-2022-25598
was published
for
apache-dolphinscheduler
(Maven)
Mar 31, 2022
Mirumee Saleor CSRF Protection Disabled
High
CVE-2019-13594
was published
for
saleor
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API