Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

265 advisories

Loading
Code execution vulnerability in HtmlUnit High
CVE-2020-5529 was published for net.sourceforge.htmlunit:htmlunit (Maven) May 21, 2020
Incomplete validation in `SparseAdd` Moderate
CVE-2021-29609 was published for tensorflow (pip) May 21, 2021
Invalid validation in `QuantizeAndDequantizeV2` Low
CVE-2021-29610 was published for tensorflow (pip) May 21, 2021
Incomplete validation in `SparseReshape` Low
CVE-2021-29611 was published for tensorflow (pip) May 21, 2021
Incomplete validation in `tf.raw_ops.CTCLoss` Moderate
CVE-2021-29613 was published for tensorflow (pip) May 21, 2021
Interpreter crash from `tf.io.decode_raw` High
CVE-2021-29614 was published for tensorflow (pip) May 21, 2021
Use of Uninitialized Resource in alg_ds Critical
CVE-2020-36432 was published for alg_ds (Rust) Aug 25, 2021
UUPSUpgradeable vulnerability in @openzeppelin/contracts Critical
CVE-2021-41264 was published for @openzeppelin/contracts (npm) Sep 15, 2021
OpenZeppelin Contracts initializer reentrancy may lead to double initialization Moderate
CVE-2022-39384 was published for @openzeppelin/contracts (npm) Dec 14, 2021
Resource Exhaustion Denial of Service in http-proxy-agent Moderate
CVE-2019-10196 was published for http-proxy-agent (npm) Jan 6, 2022
Improper Initialization in Pillow Moderate
CVE-2022-22815 was published for Pillow (pip) Jan 12, 2022
sunSUNQ
pgjdbc Does Not Check Class Instantiation when providing Plugin Classes High
CVE-2022-21724 was published for org.postgresql:postgresql (Maven) Feb 2, 2022
iSafeBlue
Improper Initialization in OpenZeppelin High
CVE-2021-46320 was published for @openzeppelin/contracts (npm) Feb 5, 2022
Improper initialization of shared resources in some Intel(R) Processors may allow an... Moderate Unreviewed
CVE-2021-0145 was published Feb 11, 2022
TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm High
CVE-2020-8918 was published for github.com/google/go-tpm (Go) Feb 11, 2022
chrisfenner
ProTip! Advisories are also available from the GraphQL API