GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
Critical
Unreviewed
CVE-2022-3491
was published
Dec 3, 2022
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in...
Critical
Unreviewed
CVE-2022-41639
was published
Dec 23, 2022
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO...
Critical
Unreviewed
CVE-2022-41838
was published
Dec 23, 2022
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of...
Critical
Unreviewed
CVE-2022-41794
was published
Dec 23, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
Critical
Unreviewed
CVE-2022-43634
was published
Mar 29, 2023
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston...
Critical
Unreviewed
CVE-2023-25181
was published
Nov 14, 2023
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality...
Critical
Unreviewed
CVE-2023-27882
was published
Nov 14, 2023
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the...
Critical
Unreviewed
CVE-2023-5908
was published
Dec 1, 2023
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used...
Critical
Unreviewed
CVE-2023-29073
was published
Nov 23, 2023
Heap-based buffer overflow in ZBar
Critical
CVE-2023-40889
was published
for
zbar
(pip)
Aug 29, 2023
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston...
Critical
Unreviewed
CVE-2023-45318
was published
Feb 20, 2024
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep...
Critical
Unreviewed
CVE-2023-5841
was published
Feb 1, 2024
A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via...
Critical
Unreviewed
CVE-2019-3568
was published
May 24, 2022
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Critical
Unreviewed
CVE-2019-5482
was published
May 24, 2022
A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An...
Critical
Unreviewed
CVE-2019-18325
was published
May 24, 2022
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character...
Critical
Unreviewed
CVE-2020-1917
was published
May 24, 2022
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers...
Critical
Unreviewed
CVE-2023-0851
was published
May 11, 2023
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office...
Critical
Unreviewed
CVE-2023-0854
was published
May 11, 2023
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A...
Critical
Unreviewed
CVE-2023-28753
was published
May 19, 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version...
Critical
Unreviewed
CVE-2023-27997
was published
Jun 13, 2023
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of...
Critical
Unreviewed
CVE-2022-48512
was published
Jul 6, 2023
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting...
Critical
Unreviewed
CVE-2023-3463
was published
Jul 19, 2023
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the...
Critical
Unreviewed
CVE-2024-4323
was published
May 20, 2024
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3...
Critical
Unreviewed
CVE-2024-29204
was published
Apr 19, 2024
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in...
Critical
Unreviewed
CVE-2023-26793
was published
May 1, 2024
ProTip!
Advisories are also available from the
GraphQL API