GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,335
Erlang
31
GitHub Actions
22
Go
2,096
Maven
5,000+
npm
3,762
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
130 advisories
Filter by severity
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function...
High
Unreviewed
CVE-2019-13135
was published
May 24, 2022
Uninitialized read in Nokogiri gem
High
CVE-2019-13117
was published
for
nokogiri
(RubyGems)
May 24, 2022
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote...
High
Unreviewed
CVE-2015-8390
was published
May 17, 2022
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which...
High
Unreviewed
CVE-2015-3414
was published
May 14, 2022
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking...
High
Unreviewed
CVE-2019-9578
was published
May 13, 2022
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could...
High
Unreviewed
CVE-2018-15911
was published
May 13, 2022
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer...
High
Unreviewed
CVE-2018-7166
was published
May 13, 2022
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows...
High
Unreviewed
CVE-2012-1891
was published
May 13, 2022
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE...
High
Unreviewed
CVE-2017-9098
was published
May 13, 2022
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG,...
High
Unreviewed
CVE-2018-6981
was published
May 13, 2022
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4...
High
Unreviewed
CVE-2015-5165
was published
May 13, 2022
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2010-2556
was published
May 13, 2022
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-2557
was published
May 13, 2022
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2010-3346
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-2559
was published
May 13, 2022
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-3343
was published
May 13, 2022
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1262
was published
May 13, 2022
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1250
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2011-1251
was published
May 13, 2022
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet...
High
Unreviewed
CVE-2011-1255
was published
May 13, 2022
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1256
was published
May 13, 2022
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1254
was published
May 13, 2022
The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6...
High
Unreviewed
CVE-2011-1266
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-3345
was published
May 13, 2022
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1963
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API