GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
248 advisories
Filter by severity
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in...
Moderate
Unreviewed
CVE-2025-12781
was published
Jan 21, 2026
loggingredactor converts non-string types to string types in logs
Low
CVE-2026-22041
was published
for
loggingredactor
(pip)
Jan 7, 2026
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had...
High
Unreviewed
CVE-2025-13720
was published
Dec 2, 2025
A type confusion vulnerability exists in the handling of the string addition (+) operation within...
High
Unreviewed
CVE-2025-62494
was published
Oct 16, 2025
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix invalid...
High
Unreviewed
CVE-2025-39880
was published
Sep 23, 2025
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a...
Critical
Unreviewed
CVE-2010-20115
was published
Aug 21, 2025
An unauthenticated remote attacker can bypass the login to the web application of the affected...
Critical
Unreviewed
CVE-2025-41648
was published
Jul 1, 2025
An unauthorized remote attacker can bypass the authentication of the affected software package by...
Critical
Unreviewed
CVE-2025-41646
was published
Jun 6, 2025
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix wrong reg type...
Moderate
Unreviewed
CVE-2022-49873
was published
May 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
perf/dwc_pcie: fix duplicate...
Moderate
Unreviewed
CVE-2025-37746
was published
May 1, 2025
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Low
Unreviewed
CVE-2023-35816
was published
Apr 28, 2025
In the Linux kernel, the following vulnerability has been resolved:
acpi: nfit: fix narrowing...
Moderate
Unreviewed
CVE-2025-22044
was published
Apr 16, 2025
Memory corruption while processing IOCTL calls.
High
Unreviewed
CVE-2024-43058
was published
Apr 7, 2025
Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0
Moderate
CVE-2025-1057
was published
for
keylime
(pip)
Feb 14, 2025
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an...
Moderate
Unreviewed
CVE-2025-20072
was published
Jan 16, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
In the Linux kernel, the following vulnerability has been resolved:
Revert "readahead: properly...
Moderate
Unreviewed
CVE-2024-57839
was published
Jan 11, 2025
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of...
High
Unreviewed
CVE-2018-9339
was published
Nov 19, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39590
was published
Sep 18, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39589
was published
Sep 18, 2024
An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy...
Low
Unreviewed
CVE-2024-26015
was published
Jul 9, 2024
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302...
High
Unreviewed
CVE-2024-35303
was published
Jun 11, 2024
OneFlow-Inc. Oneflow v0.9.1 does not display an error or warning when the oneflow.eye parameter...
Moderate
Unreviewed
CVE-2024-36735
was published
Jun 6, 2024
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
Moderate
Unreviewed
CVE-2024-21478
was published
Jun 3, 2024
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution...
High
Unreviewed
CVE-2024-5436
was published
May 31, 2024
ProTip!
Advisories are also available from the
GraphQL API