GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
319 advisories
Filter by severity
AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect...
High
Unreviewed
CVE-2017-14639
was published
May 13, 2022
The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in...
High
Unreviewed
CVE-2025-32948
was published
Apr 15, 2025
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X...
High
Unreviewed
CVE-2016-1015
was published
May 14, 2022
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and...
High
Unreviewed
CVE-2016-0985
was published
May 17, 2022
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an...
High
Unreviewed
CVE-2025-29791
was published
Apr 8, 2025
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based)...
High
Unreviewed
CVE-2025-25000
was published
Apr 4, 2025
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code...
High
Unreviewed
CVE-2024-7520
was published
Aug 6, 2024
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2018
was published
Mar 11, 2025
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2015
was published
Mar 11, 2025
Ashlar-Vellum Cobalt VC6 File Parsing Type Confusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2016
was published
Mar 11, 2025
Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2022
was published
Mar 11, 2025
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to...
High
Unreviewed
CVE-2025-1920
was published
Mar 10, 2025
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to...
High
Unreviewed
CVE-2025-2135
was published
Mar 10, 2025
jq v1.7.1 contains a stack-buffer-overflow in the decNumberCopy function within decNumber.c.
High
Unreviewed
CVE-2024-53427
was published
Feb 26, 2025
: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark...
High
Unreviewed
CVE-2024-11346
was published
Feb 13, 2025
A type confusion vulnerability has been identified in the Postscript interpreter in various...
High
Unreviewed
CVE-2024-11344
was published
Feb 13, 2025
Vulnerable OpenSSL included in cryptography wheels
High
CVE-2023-0286
was published
for
cryptography
(pip)
Feb 8, 2023
Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to...
High
Unreviewed
CVE-2025-0291
was published
Jan 8, 2025
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7...
High
Unreviewed
CVE-2012-0507
was published
May 4, 2022
ChakraCore RCE Vulnerability
High
CVE-2016-7201
was published
for
Microsoft.ChakraCore
(NuGet)
May 14, 2022
A remote code execution vulnerability exists in the way that the scripting engine handles objects...
High
Unreviewed
CVE-2019-0752
was published
May 13, 2022
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in...
High
Unreviewed
CVE-2019-11707
was published
May 24, 2022
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-21408
was published
Feb 7, 2025
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-21342
was published
Feb 7, 2025
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent...
High
Unreviewed
CVE-2024-40676
was published
Jan 28, 2025
ProTip!
Advisories are also available from the
GraphQL API