GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,494
Maven
5,000+
npm
4,131
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
346 advisories
Filter by severity
arenavec has multiple memory corruption vulnerabilities in safe APIs
High
GHSA-3632-54q8-m96x
was published
for
arenavec
(Rust)
Sep 2, 2025
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7...
High
Unreviewed
CVE-2025-53948
was published
Aug 19, 2025
A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security...
High
Unreviewed
CVE-2025-20134
was published
Aug 14, 2025
gnuplot 5.5 is affected by double free when executing print_set_output. This may result in...
High
Unreviewed
CVE-2020-25559
was published
May 24, 2022
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple...
High
Unreviewed
CVE-2025-23322
was published
Aug 6, 2025
Slice Ring Buffer and Slice Deque contains four unique double-free vulnerabilities triggered through safe APIs
High
GHSA-7mcq-f592-pf7v
was published
for
slice-deque
(Rust)
Jul 16, 2025
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker...
High
Unreviewed
CVE-2025-49688
was published
Jul 8, 2025
Double free in Microsoft Brokering File System allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-49693
was published
Jul 8, 2025
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2025-47975
was published
Jul 8, 2025
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2025-49667
was published
Jul 8, 2025
Memory corruption while processing multiple simultaneous escape calls.
High
Unreviewed
CVE-2025-27046
was published
Jul 8, 2025
Memory corruption while retrieving the CBOR data from TA.
High
Unreviewed
CVE-2025-21432
was published
Jul 8, 2025
Memory corruption while processing command message in WLAN Host.
High
Unreviewed
CVE-2025-27051
was published
Jul 8, 2025
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a...
High
Unreviewed
CVE-2022-28390
was published
Apr 4, 2022
An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 1080, 2100, 1280...
High
Unreviewed
CVE-2025-23102
was published
Jun 3, 2025
A double-free condition occurs during the cleanup of temporary image files, which can be...
High
Unreviewed
CVE-2025-5100
was published
May 23, 2025
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a...
High
Unreviewed
CVE-2022-28388
was published
Apr 4, 2022
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus,...
High
Unreviewed
CVE-2024-3446
was published
Apr 9, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: fix double...
High
Unreviewed
CVE-2024-49989
was published
Oct 21, 2024
In the Linux kernel, the following vulnerability has been resolved:
nvme: avoid double free...
High
Unreviewed
CVE-2024-41073
was published
Jul 29, 2024
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can...
High
Unreviewed
CVE-2022-40304
was published
Nov 23, 2022
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1...
High
Unreviewed
CVE-2015-5177
was published
May 17, 2022
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote...
High
Unreviewed
CVE-2017-6362
was published
May 17, 2022
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution...
High
Unreviewed
CVE-2017-9078
was published
May 13, 2022
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11...
High
Unreviewed
CVE-2017-6074
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API