GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,511
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,512
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
175 advisories
Filter by severity
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The...
Moderate
Unreviewed
CVE-2026-71391
was published
Aug 10, 2026
ImageMagick: Information Disclosure when printing profiles with debug enabled
Low
GHSA-hwf3-r46v-5ggx
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
The code to parse MIME headers for display when forwarding a message (if the setting to view all...
High
Unreviewed
CVE-2026-14899
was published
Jul 22, 2026
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is...
Low
Unreviewed
CVE-2026-44687
was published
Jul 22, 2026
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-50497
was published
Jul 14, 2026
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the...
High
Unreviewed
CVE-2026-58380
was published
Jul 6, 2026
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
High
Unreviewed
CVE-2026-12413
was published
Jul 3, 2026
UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used...
Low
Unreviewed
CVE-2026-44042
was published
Jul 1, 2026
UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB...
High
Unreviewed
CVE-2026-7831
was published
Jul 1, 2026
In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link...
Moderate
Unreviewed
CVE-2026-58374
was published
Jun 30, 2026
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list...
High
Unreviewed
CVE-2026-58014
was published
Jun 30, 2026
In the Linux kernel, the following vulnerability has been resolved:
tty: hvc_iucv: fix off-by...
Moderate
Unreviewed
CVE-2026-53306
was published
Jun 26, 2026
In the Linux kernel, the following vulnerability has been resolved:
ocfs2/dlm: fix off-by-one in...
Critical
Unreviewed
CVE-2026-53309
was published
Jun 26, 2026
RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3...
Moderate
Unreviewed
CVE-2026-56787
was published
Jun 25, 2026
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in...
High
Unreviewed
CVE-2026-56790
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
6lowpan: fix off-by-one in...
Moderate
Unreviewed
CVE-2026-53263
was published
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: fix off-by...
Critical
Unreviewed
CVE-2026-53088
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
bpf, arm64: Fix off-by-one...
High
Unreviewed
CVE-2026-53036
was published
Jun 24, 2026
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
Moderate
CVE-2026-52804
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow...
Moderate
Unreviewed
CVE-2026-8357
was published
Jun 15, 2026
nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header()...
High
Unreviewed
CVE-2026-54410
was published
Jun 14, 2026
In the Linux kernel, the following vulnerability has been resolved:
media: rockchip: rkcif: fix...
High
Unreviewed
CVE-2026-52907
was published
Jun 9, 2026
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability...
High
Unreviewed
CVE-2026-49127
was published
May 28, 2026
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix num_ops off-by-one...
Moderate
Unreviewed
CVE-2026-46066
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API