GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
105 advisories
Filter by severity
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in...
Moderate
Unreviewed
CVE-2025-5372
was published
Jul 4, 2025
Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in...
Low
Unreviewed
CVE-2026-44074
was published
May 21, 2026
An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper...
Low
Unreviewed
CVE-2026-7836
was published
May 21, 2026
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that...
Moderate
Unreviewed
CVE-2023-7346
was published
May 20, 2026
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
Critical
CVE-2026-44498
was published
for
zebrad
(Rust)
May 7, 2026
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
High
CVE-2026-33487
was published
for
github.com/russellhaering/goxmldsig
(Go)
Mar 18, 2026
libcrux-sha3: Incorrect output from SHAKE squeeze functions
High
GHSA-q29p-9pfr-j652
was published
for
libcrux-sha3
(Rust)
Mar 26, 2026
CIRCL has an incorrect calculation in secp384r1 CombinedMult
Low
CVE-2026-1229
was published
for
github.com/cloudflare/circl
(Go)
Feb 25, 2026
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an...
Moderate
Unreviewed
CVE-2024-11176
was published
Nov 20, 2024
ml-dsa's UseHint function has off by two error when r0 equals zero
Moderate
GHSA-h37v-hp6w-2pp8
was published
for
ml-dsa
(Rust)
Feb 2, 2026
soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives
High
CVE-2026-24783
was published
for
soroban-fixed-point-math
(Rust)
Jan 28, 2026
An Incorrect Calculation vulnerability in the Layer 2 Control
Protocol
Daemon (l2cpd) of...
High
Unreviewed
CVE-2026-21911
was published
Jan 15, 2026
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: don't allow...
High
Unreviewed
CVE-2024-41011
was published
Jul 18, 2024
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and...
Moderate
Unreviewed
CVE-2025-55552
was published
Sep 25, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
CVE-2025-59047
was published
for
matrix-sdk-base
(Rust)
Sep 11, 2025
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with...
Moderate
Unreviewed
CVE-2024-11407
was published
Nov 26, 2024
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that...
High
Unreviewed
CVE-2025-4435
was published
Jun 3, 2025
In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts...
High
Unreviewed
CVE-2021-45960
was published
Feb 10, 2022
Cranelift vulnerable to miscompilation of constant values in division on AArch64
Moderate
CVE-2022-31169
was published
for
cranelift-codegen
(Rust)
Jul 21, 2022
Miscompilation of `i8x16.swizzle` and `select` with v128 inputs
Moderate
CVE-2022-31104
was published
for
cranelift-codegen
(Rust)
Jun 29, 2022
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS...
High
Unreviewed
CVE-2017-12134
was published
May 13, 2022
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Floating Point...
Moderate
Unreviewed
CVE-2017-11537
was published
May 13, 2022
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in...
Moderate
Unreviewed
CVE-2017-8932
was published
May 13, 2022
Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest...
High
Unreviewed
CVE-2017-8905
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API