GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
408 advisories
Filter by severity
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate...
High
Unreviewed
CVE-2025-43715
was published
Apr 17, 2025
7-Zip through 24.09 does not report an error for certain invalid xz files, involving block flags...
Low
Unreviewed
CVE-2022-47111
was published
Apr 19, 2025
7-Zip through 24.09 does not report an error for certain invalid xz files, involving stream flags...
Low
Unreviewed
CVE-2022-47112
was published
Apr 19, 2025
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM...
High
Unreviewed
CVE-2017-11144
was published
May 14, 2022
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash...
Moderate
Unreviewed
CVE-2017-13142
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was...
High
Unreviewed
CVE-2017-17083
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was...
High
Unreviewed
CVE-2017-17085
was published
May 14, 2022
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was...
High
Unreviewed
CVE-2017-17084
was published
May 14, 2022
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic...
High
Unreviewed
CVE-2017-1000407
was published
May 14, 2022
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm...
Moderate
Unreviewed
CVE-2017-17815
was published
May 14, 2022
In loadFromXml of ShortcutPackage.java, there is a possible crash on boot due to an uncaught...
Moderate
Unreviewed
CVE-2022-20500
was published
Dec 13, 2022
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2024-4367
was published
for
pdfjs-dist
(npm)
May 7, 2024
http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
Moderate
CVE-2025-32997
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
In the Linux kernel, the following vulnerability has been resolved:
x86/fpu: Prevent state...
Moderate
Unreviewed
CVE-2021-47227
was published
May 21, 2024
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser...
Moderate
Unreviewed
CVE-2024-50602
was published
Oct 27, 2024
In setImpl of AlarmManagerService.java, there is a possible way to put a device into a boot loop...
Moderate
Unreviewed
CVE-2022-20414
was published
Nov 9, 2022
In multiple functions of many files, there is a possible obstruction of the user's ability to...
Moderate
Unreviewed
CVE-2022-20426
was published
Nov 9, 2022
In the Linux kernel, the following vulnerability has been resolved:
f2fs: check validation of...
High
Unreviewed
CVE-2024-42160
was published
Jul 30, 2024
Improper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an...
Moderate
Unreviewed
CVE-2021-33147
was published
Feb 11, 2022
Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM)...
Moderate
Unreviewed
CVE-2021-33139
was published
Feb 11, 2022
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to...
Moderate
Unreviewed
CVE-2023-32871
was published
May 6, 2024
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2025-20200
was published
May 7, 2025
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2025-20198
was published
May 7, 2025
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2025-20201
was published
May 7, 2025
Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore...
Low
Unreviewed
CVE-2024-12533
was published
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API