GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
196 advisories
Filter by severity
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could...
High
Unreviewed
CVE-2026-6726
was published
Aug 11, 2026
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to...
High
Unreviewed
CVE-2026-50337
was published
Jul 14, 2026
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
High
CVE-2026-55076
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
High
CVE-2026-46597
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
High
CVE-2026-45685
was published
for
go.opentelemetry.io/obi
(Go)
May 18, 2026
An authorized user may disable the MongoDB server by issuing a query against a collection that...
High
Unreviewed
CVE-2026-25613
was published
Feb 10, 2026
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had...
High
Unreviewed
CVE-2025-13720
was published
Dec 2, 2025
A type confusion vulnerability exists in the handling of the string addition (+) operation within...
High
Unreviewed
CVE-2025-62494
was published
Oct 16, 2025
In the Linux kernel, the following vulnerability has been resolved:
libceph: fix invalid...
High
Unreviewed
CVE-2025-39880
was published
Sep 23, 2025
Memory corruption while processing IOCTL calls.
High
Unreviewed
CVE-2024-43058
was published
Apr 7, 2025
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of...
High
Unreviewed
CVE-2018-9339
was published
Nov 19, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39589
was published
Sep 18, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39590
was published
Sep 18, 2024
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302...
High
Unreviewed
CVE-2024-35303
was published
Jun 11, 2024
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution...
High
Unreviewed
CVE-2024-5436
was published
May 31, 2024
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage...
High
Unreviewed
CVE-2024-28130
was published
Apr 23, 2024
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
High
Unreviewed
CVE-2023-33101
was published
Apr 1, 2024
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201...
High
Unreviewed
CVE-2023-45204
was published
Oct 10, 2023
Weaviate denial of service vulnerability
High
CVE-2023-38976
was published
for
github.com/weaviate/weaviate
(Go)
Aug 22, 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write...
High
Unreviewed
CVE-2023-21651
was published
Aug 8, 2023
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
High
Unreviewed
CVE-2023-21627
was published
Aug 8, 2023
Memory corruption in Video while calling APIs with different instance ID than the one received in...
High
Unreviewed
CVE-2023-21638
was published
Jul 4, 2023
Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder
High
CVE-2022-1642
was published
for
github.com/apple/swift-corelibs-foundation
(Swift)
Jun 7, 2023
Memory corruption in Audio due to incorrect type cast during audio use-cases.
High
Unreviewed
CVE-2022-33240
was published
Jun 6, 2023
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic...
High
Unreviewed
CVE-2023-28162
was published
Jun 2, 2023
ProTip!
Advisories are also available from the
GraphQL API