GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
115 advisories
Filter by severity
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.19. It allows...
High
Unreviewed
CVE-2022-47517
was published
Dec 18, 2022
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and...
Critical
Unreviewed
CVE-2016-10160
was published
May 14, 2022
GoBGP panics due to a zero value for softwareVersionLen
High
CVE-2025-43971
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP does not verify that the input length
Moderate
CVE-2025-43973
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: BPF: Fix off-by...
Moderate
Unreviewed
CVE-2025-37893
was published
Apr 18, 2025
wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64
Low
CVE-2023-27477
was published
for
cranelift-codegen
(Rust)
Mar 9, 2023
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Low
CVE-2023-41880
was published
for
wasmtime
(Rust)
Sep 14, 2023
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c....
Moderate
Unreviewed
CVE-2022-3821
was published
Nov 9, 2022
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading...
High
Unreviewed
CVE-2022-3872
was published
Nov 8, 2022
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects...
Critical
Unreviewed
CVE-2021-46848
was published
Oct 24, 2022
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status...
Moderate
Unreviewed
CVE-2025-47711
was published
Jun 9, 2025
FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in...
Moderate
Unreviewed
CVE-2024-31585
was published
Apr 17, 2024
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in...
Moderate
Unreviewed
CVE-2025-52497
was published
Jul 4, 2025
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer...
Moderate
Unreviewed
CVE-2025-54349
was published
Aug 3, 2025
ImageMagick has a Heap Buffer Overflow in InterpretImageFilename
Low
CVE-2025-53014
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ProTip!
Advisories are also available from the
GraphQL API