GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
150 advisories
Filter by severity
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts...
High
Unreviewed
CVE-2026-14957
was published
Sep 2, 2026
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-xqqh-3w52-q8p7
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails....
Moderate
Unreviewed
CVE-2026-77641
was published
Aug 20, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because...
Low
Unreviewed
CVE-2026-26080
was published
Jul 20, 2026
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null...
Moderate
Unreviewed
CVE-2026-61857
was published
Jul 11, 2026
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
Moderate
CVE-2026-35339
was published
for
uu_chmod
(Rust)
Jul 6, 2026
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile...
High
Unreviewed
CVE-2026-11972
was published
Jun 24, 2026
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
Moderate
CVE-2026-46521
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
High
CVE-2026-40092
was published
for
nimiq-keys
(Rust)
May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an...
High
Unreviewed
CVE-2025-29938
was published
May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an...
High
Unreviewed
CVE-2025-0028
was published
May 15, 2026
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed...
High
Unreviewed
CVE-2026-40060
was published
May 13, 2026
Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13...
Moderate
Unreviewed
CVE-2026-20793
was published
May 12, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
uutils coreutils has an Unchecked Return Value Issue
Low
CVE-2026-35344
was published
for
coreutils
(Rust)
Apr 22, 2026
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
Moderate
CVE-2026-29905
was published
for
getkirby/cms
(Composer)
Mar 27, 2026
•
withdrawn
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation...
Moderate
Unreviewed
CVE-2026-23301
was published
Mar 25, 2026
ImageMagick has uninitialized pointer dereference in JBIG decoder
High
CVE-2026-28691
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
Nokogiri does not check the return value from xmlC14NExecute
Moderate
CVE-2026-79772
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18...
High
Unreviewed
CVE-2026-0723
was published
Jan 22, 2026
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX...
High
Unreviewed
CVE-2026-21920
was published
Jan 15, 2026
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and...
High
Unreviewed
CVE-2026-0421
was published
Jan 15, 2026
ProTip!
Advisories are also available from the
GraphQL API