GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
172 advisories
Filter by severity
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of...
High
Unreviewed
CVE-2018-9339
was published
Nov 19, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39589
was published
Sep 18, 2024
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP...
High
Unreviewed
CVE-2024-39590
was published
Sep 18, 2024
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the...
High
Unreviewed
CVE-2017-0037
was published
May 17, 2022
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via ...
High
Unreviewed
CVE-2017-8291
was published
May 14, 2022
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage...
High
Unreviewed
CVE-2024-28130
was published
Apr 23, 2024
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302...
High
Unreviewed
CVE-2024-35303
was published
Jun 11, 2024
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
High
Unreviewed
CVE-2023-21627
was published
Aug 8, 2023
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
High
Unreviewed
CVE-2023-33101
was published
Apr 1, 2024
Memory corruption in Graphics while importing a file.
High
Unreviewed
CVE-2023-21665
was published
May 2, 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write...
High
Unreviewed
CVE-2023-21651
was published
Aug 8, 2023
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to...
High
Unreviewed
CVE-2018-6157
was published
May 24, 2022
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201...
High
Unreviewed
CVE-2023-45204
was published
Oct 10, 2023
Memory corruption in Video while calling APIs with different instance ID than the one received in...
High
Unreviewed
CVE-2023-21638
was published
Jul 4, 2023
Memory corruption in Audio due to incorrect type cast during audio use-cases.
High
Unreviewed
CVE-2022-33240
was published
Jun 6, 2023
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic...
High
Unreviewed
CVE-2023-28162
was published
Jun 2, 2023
Memory corruption due to incorrect type conversion or cast in audio while using audio playback...
High
Unreviewed
CVE-2022-33301
was published
Apr 13, 2023
An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A...
High
Unreviewed
CVE-2019-5053
was published
May 24, 2022
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases,...
High
Unreviewed
CVE-2020-10735
was published
Sep 10, 2022
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte...
High
Unreviewed
CVE-2022-32547
was published
Jun 17, 2022
Possible denial of service due to incorrectly decoding hex data for the SIB2 OTA message and...
High
Unreviewed
CVE-2021-30300
was published
Jan 14, 2022
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a...
High
Unreviewed
CVE-2018-14379
was published
May 13, 2022
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID...
High
Unreviewed
CVE-2022-40531
was published
Mar 10, 2023
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions...
High
Unreviewed
CVE-2015-5219
was published
May 13, 2022
A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local...
High
Unreviewed
CVE-2022-41668
was published
Nov 4, 2022
ProTip!
Advisories are also available from the
GraphQL API