GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
67 advisories
Filter by severity
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Moderate
GHSA-xqqh-3w52-q8p7
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails....
Moderate
Unreviewed
CVE-2026-77641
was published
Aug 20, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Moderate
CVE-2026-62909
was published
for
Microsoft.NETCore.App.Runtime.linux-arm
(NuGet)
Aug 11, 2026
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null...
Moderate
Unreviewed
CVE-2026-61857
was published
Jul 11, 2026
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
Moderate
CVE-2026-35339
was published
for
uu_chmod
(Rust)
Jul 6, 2026
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
Moderate
CVE-2026-46521
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13...
Moderate
Unreviewed
CVE-2026-20793
was published
May 12, 2026
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
Moderate
CVE-2026-29905
was published
for
getkirby/cms
(Composer)
Mar 27, 2026
•
withdrawn
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation...
Moderate
Unreviewed
CVE-2026-23301
was published
Mar 25, 2026
Nokogiri does not check the return value from xmlC14NExecute
Moderate
CVE-2026-79772
was published
for
nokogiri
(RubyGems)
Feb 18, 2026
A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of...
Moderate
Unreviewed
CVE-2025-11839
was published
Oct 16, 2025
An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy...
Moderate
Unreviewed
CVE-2025-55146
was published
Sep 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
iwlwifi: Add missing check...
Moderate
Unreviewed
CVE-2025-38602
was published
Aug 19, 2025
Failure to handle the error status returned by the buffer management APIs in SiLabs EmberZNet...
Moderate
Unreviewed
CVE-2025-1394
was published
Jul 30, 2025
In the Linux kernel, the following vulnerability has been resolved:
ACPI: PPTT: Fix to avoid...
Moderate
Unreviewed
CVE-2023-53070
was published
May 2, 2025
In the Linux kernel, the following vulnerability has been resolved:
nfsd: don't ignore the...
Moderate
Unreviewed
CVE-2025-22026
was published
Apr 16, 2025
In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the...
Moderate
Unreviewed
CVE-2025-32414
was published
Apr 8, 2025
An attacker with low privileges can manipulate the requested memory size, causing the application...
Moderate
Unreviewed
CVE-2024-12650
was published
Mar 5, 2025
list_item_verbose in tar/util.c in libarchive through 3.7.7 does not check an strftime return...
Moderate
Unreviewed
CVE-2025-25724
was published
Mar 2, 2025
A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc()...
Moderate
Unreviewed
CVE-2024-45775
was published
Feb 18, 2025
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in...
Moderate
Unreviewed
CVE-2024-1545
was published
Aug 30, 2024
Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to...
Moderate
Unreviewed
CVE-2023-40067
was published
Aug 14, 2024
In the Linux kernel, the following vulnerability has been resolved:
bpf: Take return from...
Moderate
Unreviewed
CVE-2024-42068
was published
Jul 29, 2024
In the Linux kernel, the following vulnerability has been resolved:
bpf: Take return from...
Moderate
Unreviewed
CVE-2024-42067
was published
Jul 29, 2024
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the...
Moderate
Unreviewed
CVE-2024-37039
was published
Jun 12, 2024
ProTip!
Advisories are also available from the
GraphQL API