GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
65 advisories
Filter by severity
In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts...
High
Unreviewed
CVE-2026-14957
was published
Sep 2, 2026
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile...
High
Unreviewed
CVE-2026-11972
was published
Jun 24, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
High
CVE-2026-40092
was published
for
nimiq-keys
(Rust)
May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an...
High
Unreviewed
CVE-2025-29938
was published
May 15, 2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an...
High
Unreviewed
CVE-2025-0028
was published
May 15, 2026
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed...
High
Unreviewed
CVE-2026-40060
was published
May 13, 2026
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
High
CVE-2026-34065
was published
for
nimiq-primitives
(Rust)
Apr 22, 2026
sigstore-ruby verifier returns success for DSSE bundles with mismatched in-toto subject digest
High
CVE-2026-31830
was published
for
sigstore
(RubyGems)
Mar 11, 2026
ImageMagick has uninitialized pointer dereference in JBIG decoder
High
CVE-2026-28691
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18...
High
Unreviewed
CVE-2026-0723
was published
Jan 22, 2026
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX...
High
Unreviewed
CVE-2026-21920
was published
Jan 15, 2026
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and...
High
Unreviewed
CVE-2026-0421
was published
Jan 15, 2026
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash...
High
Unreviewed
CVE-2024-0743
was published
Jan 23, 2024
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over...
High
Unreviewed
CVE-2025-1933
was published
Mar 4, 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products,...
High
Unreviewed
CVE-2020-7247
was published
May 24, 2022
When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed...
High
Unreviewed
CVE-2025-61935
was published
Oct 15, 2025
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser...
High
Unreviewed
CVE-2021-34585
was published
May 24, 2022
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value,...
High
Unreviewed
CVE-2021-3998
was published
Aug 25, 2022
dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the...
High
Unreviewed
CVE-2017-6964
was published
May 13, 2022
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the...
High
Unreviewed
CVE-2007-5191
was published
May 1, 2022
In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return...
High
Unreviewed
CVE-2023-23003
was published
Mar 1, 2023
Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a...
High
Unreviewed
CVE-2024-45419
was published
Nov 19, 2024
In the Linux kernel, the following vulnerability has been resolved:
mailbox: mtk-cmdq: Fix...
High
Unreviewed
CVE-2024-39492
was published
Jul 10, 2024
An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges...
High
Unreviewed
CVE-2023-47480
was published
Sep 20, 2024
ProTip!
Advisories are also available from the
GraphQL API