GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,051
Maven
5,000+
npm
4,791
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,145
Swift
50
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,435 advisories
Filter by severity
Incorrect boundary conditions in the Web Audio component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2026-2773
was published
Feb 24, 2026
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This...
Critical
Unreviewed
CVE-2026-2778
was published
Feb 24, 2026
Incorrect boundary conditions in the Networking: JAR component. This vulnerability affects...
Critical
Unreviewed
CVE-2026-2779
was published
Feb 24, 2026
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability affects...
Critical
Unreviewed
CVE-2026-2788
was published
Feb 24, 2026
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External...
Critical
Unreviewed
CVE-2026-2776
was published
Feb 24, 2026
In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds...
Critical
Unreviewed
CVE-2026-0106
was published
Feb 5, 2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in...
Critical
Unreviewed
CVE-2026-24798
was published
Jan 27, 2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in...
Critical
Unreviewed
CVE-2026-24794
was published
Jan 27, 2026
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability...
Critical
Unreviewed
CVE-2026-0879
was published
Jan 13, 2026
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence...
Critical
Unreviewed
CVE-2026-0892
was published
Jan 13, 2026
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function...
Critical
Unreviewed
CVE-2025-14964
was published
Dec 19, 2025
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox <...
Critical
Unreviewed
CVE-2025-14330
was published
Dec 9, 2025
Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence...
Critical
Unreviewed
CVE-2025-13027
was published
Nov 11, 2025
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory...
Critical
Unreviewed
CVE-2025-11721
was published
Oct 14, 2025
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of...
Critical
Unreviewed
CVE-2025-21483
was published
Sep 24, 2025
The issue was addressed with improved memory handling. This issue is fixed in tvOS 26, Safari 26,...
Critical
Unreviewed
CVE-2025-43343
was published
Sep 16, 2025
In BootRom, there's a possible missing payload size check. This could lead to memory buffer...
Critical
Unreviewed
CVE-2022-38696
was published
Sep 2, 2025
In FDL1, there is a possible missing payload size check. This could lead to memory buffer...
Critical
Unreviewed
CVE-2022-38693
was published
Sep 2, 2025
In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This...
Critical
Unreviewed
CVE-2022-38692
was published
Sep 2, 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in...
Critical
Unreviewed
CVE-2025-7775
was published
Aug 26, 2025
In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and...
Critical
Unreviewed
CVE-2025-29366
was published
Aug 22, 2025
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence...
Critical
Unreviewed
CVE-2025-9187
was published
Aug 19, 2025
An attacker was able to perform memory corruption in the GMP process which processes encrypted...
Critical
Unreviewed
CVE-2025-9179
was published
Aug 19, 2025
A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function...
Critical
Unreviewed
CVE-2025-8760
was published
Aug 13, 2025
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.6, iOS...
Critical
Unreviewed
CVE-2025-43186
was published
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API