GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
124 advisories
Filter by severity
An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior...
Moderate
Unreviewed
CVE-2025-7259
was published
Jul 7, 2025
In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type...
Moderate
Unreviewed
CVE-2022-3676
was published
Oct 24, 2022
An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux...
Moderate
Unreviewed
CVE-2022-3903
was published
Nov 15, 2022
A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-30445
was published
Apr 29, 2025
Some Honor products are affected by type confusion vulnerability, successful exploitation could...
Moderate
Unreviewed
CVE-2023-23443
was published
Dec 29, 2023
Browser is affected by type confusion vulnerability, successful exploitation of this...
Moderate
Unreviewed
CVE-2025-2197
was published
Apr 17, 2025
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote...
Moderate
Unreviewed
CVE-2025-32352
was published
Apr 5, 2025
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-29806
was published
Mar 23, 2025
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-54507
was published
Jan 28, 2025
Prototype Pollution in node-jsonpointer
Moderate
CVE-2021-23807
was published
for
jsonpointer
(npm)
Nov 8, 2021
An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type...
Moderate
Unreviewed
CVE-2024-37603
was published
Feb 14, 2025
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Moderate
Unreviewed
CVE-2025-21279
was published
Feb 7, 2025
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Moderate
Unreviewed
CVE-2025-21225
was published
Jan 14, 2025
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security...
Moderate
Unreviewed
CVE-2024-13275
was published
Jan 9, 2025
OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of...
Moderate
Unreviewed
CVE-2023-24599
was published
May 29, 2023
Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device`
Moderate
GHSA-3qx8-rv27-j6gp
was published
for
kvm-ioctls
(Rust)
Dec 23, 2024
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena...
Moderate
Unreviewed
CVE-2019-13519
was published
May 24, 2022
Jenkins item creation restriction bypass vulnerability
Moderate
CVE-2024-47804
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Oct 2, 2024
In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from...
Moderate
Unreviewed
CVE-2024-34742
was published
Aug 16, 2024
Wrong type for `Linker`-define functions when used across two `Engine`s
Moderate
CVE-2021-39219
was published
for
wasmtime
(pip)
Sep 20, 2021
`CHECK`-failures in binary ops in Tensorflow
Moderate
CVE-2022-23583
was published
for
tensorflow
(pip)
Feb 10, 2022
In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to...
Moderate
Unreviewed
CVE-2024-20106
was published
Nov 4, 2024
marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause...
Moderate
Unreviewed
CVE-2023-50433
was published
Apr 30, 2024
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot...
Moderate
Unreviewed
CVE-2024-7824
was published
Oct 3, 2024
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot...
Moderate
Unreviewed
CVE-2024-7825
was published
Oct 3, 2024
ProTip!
Advisories are also available from the
GraphQL API