GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
397 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
f2fs: check validation of...
High
Unreviewed
CVE-2024-42160
was published
Jul 30, 2024
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop...
Moderate
Unreviewed
CVE-2022-20414
was published
Nov 9, 2022
In multiple functions of many files, there is a possible obstruction of the user's ability to...
Moderate
Unreviewed
CVE-2022-20426
was published
Nov 9, 2022
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser...
Moderate
Unreviewed
CVE-2024-50602
was published
Oct 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
x86/fpu: Prevent state...
Moderate
Unreviewed
CVE-2021-47227
was published
May 21, 2024
http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
Moderate
CVE-2025-32997
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2024-4367
was published
for
pdfjs-dist
(npm)
May 7, 2024
In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught...
Moderate
Unreviewed
CVE-2022-20500
was published
Dec 13, 2022
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm...
Moderate
Unreviewed
CVE-2017-17815
was published
May 14, 2022
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic...
High
Unreviewed
CVE-2017-1000407
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was...
High
Unreviewed
CVE-2017-17085
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was...
High
Unreviewed
CVE-2017-17084
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was...
High
Unreviewed
CVE-2017-17083
was published
May 14, 2022
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash...
Moderate
Unreviewed
CVE-2017-13142
was published
May 14, 2022
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM...
High
Unreviewed
CVE-2017-11144
was published
May 14, 2022
7-Zip through 24.09 does not report an error for certain invalid xz files, involving stream flags...
Low
Unreviewed
CVE-2022-47112
was published
Apr 19, 2025
7-Zip through 24.09 does not report an error for certain invalid xz files, involving block flags...
Low
Unreviewed
CVE-2022-47111
was published
Apr 19, 2025
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate...
High
Unreviewed
CVE-2025-43715
was published
Apr 17, 2025
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not...
High
Unreviewed
CVE-2014-1737
was published
May 13, 2022
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP)...
High
Unreviewed
CVE-2025-0128
was published
Apr 11, 2025
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2025-30660
was published
Apr 9, 2025
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol...
Moderate
Unreviewed
CVE-2025-30655
was published
Apr 9, 2025
An Improper Check for Unusual or Exceptional Conditions vulnerability in routing protocol daemon ...
Moderate
Unreviewed
CVE-2025-21597
was published
Apr 9, 2025
An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet...
High
Unreviewed
CVE-2025-21594
was published
Apr 9, 2025
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to...
High
Unreviewed
CVE-2025-2704
was published
Apr 2, 2025
ProTip!
Advisories are also available from the
GraphQL API