GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
185 advisories
Filter by severity
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10...
High
Unreviewed
CVE-2016-7655
was published
May 17, 2022
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and...
High
Unreviewed
CVE-2017-2962
was published
May 17, 2022
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to...
High
Unreviewed
CVE-2018-6157
was published
May 24, 2022
Incorrect Privilege Assignment in Jenkins Script Security Plugin
High
CVE-2019-10355
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A...
High
Unreviewed
CVE-2019-5053
was published
May 24, 2022
A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to...
High
Unreviewed
CVE-2020-7081
was published
May 24, 2022
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or...
High
Unreviewed
CVE-2020-16103
was published
May 24, 2022
Incorrect pointer argument passed to trusted application TA could result in un-intended memory...
High
Unreviewed
CVE-2021-1923
was published
May 24, 2022
Possible out of bounds read due to improper typecasting while handling page fault for global...
High
Unreviewed
CVE-2021-35091
was published
Jun 15, 2022
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte...
High
Unreviewed
CVE-2022-32547
was published
Jun 17, 2022
pg-native and libpq vulnerable to uncontrolled resource consumption
High
CVE-2022-25852
was published
for
libpq
(npm)
Jun 18, 2022
Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon...
High
Unreviewed
CVE-2022-22102
was published
Sep 3, 2022
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases,...
High
Unreviewed
CVE-2020-10735
was published
Sep 10, 2022
Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation
High
GHSA-5c6q-f783-h888
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Sep 30, 2022
•
withdrawn
com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution
High
CVE-2022-41828
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Oct 12, 2022
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local...
High
Unreviewed
CVE-2022-41668
was published
Nov 4, 2022
Memory corruption in display driver due to incorrect type casting while accessing the fence...
High
Unreviewed
CVE-2022-25715
was published
Jan 9, 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID...
High
Unreviewed
CVE-2022-40531
was published
Mar 10, 2023
Memory corruption due to incorrect type conversion or cast in audio while using audio playback...
High
Unreviewed
CVE-2022-33301
was published
Apr 13, 2023
Memory corruption in Graphics while importing a file.
High
Unreviewed
CVE-2023-21665
was published
May 2, 2023
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to...
High
Unreviewed
CVE-2023-25737
was published
Jun 2, 2023
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic...
High
Unreviewed
CVE-2023-28162
was published
Jun 2, 2023
Memory corruption in Audio due to incorrect type cast during audio use-cases.
High
Unreviewed
CVE-2022-33240
was published
Jun 6, 2023
Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder
High
CVE-2022-1642
was published
for
github.com/apple/swift-corelibs-foundation
(Swift)
Jun 7, 2023
Memory corruption in Video while calling APIs with different instance ID than the one received in...
High
Unreviewed
CVE-2023-21638
was published
Jul 4, 2023
ProTip!
Advisories are also available from the
GraphQL API