GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
78 advisories
Filter by severity
FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP...
Moderate
Unreviewed
CVE-2026-75145
was published
Aug 19, 2026
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026...
Moderate
Unreviewed
CVE-2026-21069
was published
Aug 10, 2026
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The ...
Moderate
Unreviewed
CVE-2026-19879
was published
Aug 14, 2026
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The...
Moderate
Unreviewed
CVE-2026-6426
was published
Aug 11, 2026
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
Moderate
CVE-2026-53466
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 31, 2026
jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass
High
CVE-2026-4602
was published
for
jsrsasign
(npm)
Mar 23, 2026
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
Moderate
CVE-2026-53923
was published
for
vllm
(pip)
Jun 17, 2026
In the Linux kernel, the following vulnerability has been resolved:
RDMA/umem: Fix truncation...
High
Unreviewed
CVE-2026-53133
was published
Jun 25, 2026
iskorotkov/avro: Integer Overflow in Decoder
High
CVE-2026-46384
was published
for
github.com/iskorotkov/avro/v2
(Go)
May 18, 2026
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an...
High
Unreviewed
CVE-2026-24192
was published
May 26, 2026
Wasmtime has host data leakage with 64-bit tables and Winch
Low
CVE-2026-34945
was published
for
wasmtime
(Rust)
Apr 9, 2026
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt...
Moderate
Unreviewed
CVE-2026-4931
was published
Apr 7, 2026
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server...
High
Unreviewed
CVE-2026-24174
was published
Apr 7, 2026
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated...
Moderate
Unreviewed
CVE-2023-28063
was published
Feb 6, 2024
Windows Kernel Local Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2020-17087
was published
May 24, 2022
Soroban: Muxed address<->ScVal conversions may break after a conversion failure
Low
GHSA-pm4j-7r4q-ccg8
was published
for
soroban-env-host
(Rust)
Mar 7, 2026
ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder
High
CVE-2026-25989
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
Windows MSHTML Platform Remote Code Execution Vulnerability
High
Unreviewed
CVE-2021-33742
was published
May 24, 2022
CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
High
CVE-2025-58063
was published
for
github.com/coredns/coredns
(Go)
Sep 9, 2025
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized...
High
Unreviewed
CVE-2025-53733
was published
Aug 12, 2025
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does...
High
Unreviewed
CVE-2017-7308
was published
May 14, 2022
The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which...
High
Unreviewed
CVE-2021-32996
was published
Jan 11, 2022
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote...
Critical
Unreviewed
CVE-2016-3074
was published
May 14, 2022
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49093
was published
Dec 12, 2024
Incorrect code generation could have led to unexpected numeric conversions and potential...
High
Unreviewed
CVE-2024-1552
was published
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API