GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
909 advisories
Filter by severity
In some cases, the ktrace facility will log the contents of kernel structures to userspace. In...
Moderate
Unreviewed
CVE-2025-0662
was published
Jan 30, 2025
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to...
High
Unreviewed
CVE-2025-22880
was published
Feb 7, 2025
Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to...
High
Unreviewed
CVE-2025-0611
was published
Jan 22, 2025
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via...
Critical
Unreviewed
CVE-2019-3568
was published
May 24, 2022
A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow...
High
Unreviewed
CVE-2023-27911
was published
Jul 6, 2023
D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution...
High
Unreviewed
CVE-2023-32140
was published
May 3, 2024
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in...
Critical
Unreviewed
CVE-2021-23165
was published
Mar 17, 2022
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow...
Critical
Unreviewed
CVE-2024-50698
was published
Jan 25, 2025
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component...
Critical
Unreviewed
CVE-2024-55192
was published
Jan 24, 2025
In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application...
High
Unreviewed
CVE-2023-40222
was published
Feb 5, 2025
Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high...
High
Unreviewed
CVE-2024-22453
was published
Mar 19, 2024
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the...
Moderate
Unreviewed
CVE-2023-2241
was published
Apr 22, 2023
A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force...
High
Unreviewed
CVE-2024-8594
was published
Oct 30, 2024
A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can...
High
Unreviewed
CVE-2024-8591
was published
Oct 30, 2024
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through...
Moderate
Unreviewed
CVE-2024-33505
was published
Nov 12, 2024
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a...
High
Unreviewed
CVE-2024-12179
was published
Dec 17, 2024
A maliciously crafted DWF file, when parsed through Autodesk Navisworks, can be used to cause a...
High
Unreviewed
CVE-2024-12670
was published
Dec 17, 2024
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a...
High
Unreviewed
CVE-2024-12669
was published
Dec 17, 2024
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted...
High
Unreviewed
CVE-2024-10525
was published
Oct 30, 2024
A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force...
High
Unreviewed
CVE-2024-7673
was published
Sep 30, 2024
A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Navisworks, can force...
High
Unreviewed
CVE-2024-7674
was published
Sep 30, 2024
Windows Cryptographic Services Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-30020
was published
May 14, 2024
LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the...
High
Unreviewed
CVE-2019-15690
was published
Jan 24, 2025
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could...
Moderate
Unreviewed
CVE-2025-20128
was published
Jan 22, 2025
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in...
Moderate
Unreviewed
CVE-2020-12819
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API