GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,973
NuGet
715
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
82 advisories
Filter by severity
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote...
Critical
Unreviewed
CVE-2025-20260
was published
Jun 18, 2025
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered...
Critical
Unreviewed
CVE-2025-47868
was published
Jun 16, 2025
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check....
Critical
Unreviewed
CVE-2025-20672
was published
Jun 2, 2025
A malicious actor with access to the management network could execute a remote code execution ...
Critical
Unreviewed
CVE-2025-23123
was published
May 19, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow...
Critical
Unreviewed
CVE-2024-50698
was published
Jan 25, 2025
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component...
Critical
Unreviewed
CVE-2024-55192
was published
Jan 24, 2025
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper...
Critical
Unreviewed
CVE-2024-12084
was published
Jan 15, 2025
A vulnerability has been identified in Opcenter Execution Foundation (All versions), Opcenter...
Critical
Unreviewed
CVE-2024-49775
was published
Dec 16, 2024
Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability....
Critical
Unreviewed
CVE-2024-6246
was published
Nov 22, 2024
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
Critical
Unreviewed
CVE-2023-29125
was published
Nov 5, 2024
The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC...
Critical
Unreviewed
CVE-2024-38812
was published
Sep 17, 2024
A vulnerability has been identified in SIMATIC Information Server 2022 (All versions), SIMATIC...
Critical
Unreviewed
CVE-2024-33698
was published
Sep 10, 2024
Windows Network Virtualization Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2024-38160
was published
Aug 13, 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2024-38077
was published
Jul 9, 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2024-38076
was published
Jul 9, 2024
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC...
Critical
Unreviewed
CVE-2024-37080
was published
Jun 18, 2024
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the...
Critical
Unreviewed
CVE-2024-4323
was published
May 20, 2024
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in...
Critical
Unreviewed
CVE-2024-32615
was published
May 14, 2024
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called...
Critical
Unreviewed
CVE-2024-32621
was published
May 14, 2024
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of...
Critical
Unreviewed
CVE-2024-29157
was published
May 14, 2024
wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault...
Critical
Unreviewed
CVE-2024-34249
was published
May 6, 2024
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in...
Critical
Unreviewed
CVE-2023-26793
was published
May 1, 2024
A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3...
Critical
Unreviewed
CVE-2024-24996
was published
Apr 19, 2024
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3...
Critical
Unreviewed
CVE-2024-29204
was published
Apr 19, 2024
zlog 1.2.16 has a heap-based buffer overflow in struct zlog_rule_s while creating a new rule that...
Critical
Unreviewed
CVE-2024-22857
was published
Mar 7, 2024
ProTip!
Advisories are also available from the
GraphQL API