GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,303
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
669
pip
3,430
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
12,821 advisories
Filter by severity
The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS...
Moderate
Unreviewed
CVE-2016-4454
was published
May 13, 2022
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in...
Moderate
Unreviewed
CVE-2016-4439
was published
May 13, 2022
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU...
Moderate
Unreviewed
CVE-2016-4441
was published
May 13, 2022
Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows...
High
Unreviewed
CVE-2011-2806
was published
May 13, 2022
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not...
Critical
Unreviewed
CVE-2018-14362
was published
May 13, 2022
rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory...
High
Unreviewed
CVE-2017-14398
was published
May 13, 2022
Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token...
Moderate
Unreviewed
CVE-2011-2347
was published
May 13, 2022
Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check,...
Moderate
Unreviewed
CVE-2011-2348
was published
May 13, 2022
Google Chrome before 12.0.742.91 does not properly implement history deletion, which allows...
Moderate
Unreviewed
CVE-2011-1817
was published
May 13, 2022
Google Chrome before 11.0.696.71 does not properly implement the GPU command buffer, which allows...
High
Unreviewed
CVE-2011-1806
was published
May 13, 2022
Stack buffer overflow in httpd in Asuswrt-Merlin firmware 380.67_0RT-AC5300 and earlier for ASUS...
High
Unreviewed
CVE-2017-12754
was published
May 13, 2022
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to...
Moderate
Unreviewed
CVE-2017-11548
was published
May 13, 2022
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to...
Moderate
Unreviewed
CVE-2017-11331
was published
May 13, 2022
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of...
Moderate
Unreviewed
CVE-2016-4804
was published
May 13, 2022
The regular-expression functionality in Google Chrome before 10.0.648.127 does not properly...
High
Unreviewed
CVE-2011-1285
was published
May 13, 2022
The video functionality in Google Chrome before 10.0.648.127 allows remote attackers to cause a...
High
Unreviewed
CVE-2011-1198
was published
May 13, 2022
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier,...
Moderate
Unreviewed
CVE-2010-4008
was published
May 13, 2022
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4...
Critical
Unreviewed
CVE-2016-9400
was published
May 13, 2022
An invalid memory address dereference was discovered in the lt_prediction function of libfaad...
Moderate
Unreviewed
CVE-2018-20358
was published
May 13, 2022
An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of...
Moderate
Unreviewed
CVE-2018-20359
was published
May 13, 2022
An invalid memory address dereference was discovered in the hf_assembly function of libfaad...
Moderate
Unreviewed
CVE-2018-20361
was published
May 13, 2022
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a...
High
Unreviewed
CVE-2015-6152
was published
May 13, 2022
An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the...
Moderate
Unreviewed
CVE-2018-7726
was published
May 13, 2022
An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered...
Moderate
Unreviewed
CVE-2018-7725
was published
May 13, 2022
The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0...
High
Unreviewed
CVE-2017-16927
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API