GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,233 advisories
Filter by severity
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC...
Critical
Unreviewed
CVE-2024-37080
was published
Jun 18, 2024
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker...
High
Unreviewed
CVE-2024-3516
was published
Apr 10, 2024
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at...
High
Unreviewed
CVE-2024-46264
was published
Oct 1, 2024
Delta Electronics CNCSoft-G2 Version 2.1.0.16 and prior lacks proper
validation of the length of...
High
Unreviewed
CVE-2024-12858
was published
Mar 13, 2025
A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0...
Moderate
Unreviewed
CVE-2024-41437
was published
Jul 30, 2024
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote...
High
Unreviewed
CVE-2025-0434
was published
Jan 15, 2025
Artifex Ghostscript before 10.0.3.0 has a heap-based pointer disclosure (observable in a...
Low
Unreviewed
CVE-2024-29508
was published
Jul 3, 2024
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent...
High
Unreviewed
CVE-2024-22058
was published
May 31, 2024
A Structured Exception Handler based buffer overflow vulnerability exists in Effectmatrix Total...
Moderate
Unreviewed
CVE-2024-53310
was published
Feb 14, 2025
A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3...
Critical
Unreviewed
CVE-2024-24996
was published
Apr 19, 2024
In wlan driver, there is a possible missing params check. This could lead to local denial of...
Moderate
Unreviewed
CVE-2022-42783
was published
Feb 12, 2023
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local...
Moderate
Unreviewed
CVE-2025-31164
was published
Mar 28, 2025
Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow...
High
Unreviewed
CVE-2025-24439
was published
Mar 11, 2025
Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow...
High
Unreviewed
CVE-2025-24443
was published
Mar 11, 2025
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2...
High
Unreviewed
CVE-2025-29070
was published
Apr 1, 2025
A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability...
High
Unreviewed
CVE-2025-29069
was published
Apr 1, 2025
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-21222
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-21221
was published
Apr 8, 2025
Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to...
High
Unreviewed
CVE-2025-26639
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-21205
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an...
High
Unreviewed
CVE-2025-26668
was published
Apr 8, 2025
Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow...
High
Unreviewed
CVE-2025-27199
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-26666
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-26674
was published
Apr 8, 2025
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-27490
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API