GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
563 advisories
Filter by severity
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable...
Critical
Unreviewed
CVE-2022-26486
was published
Dec 22, 2022
Session history navigations may have led to a use-after-free and potentially exploitable crash....
Critical
Unreviewed
CVE-2022-34470
was published
Dec 22, 2022
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may...
Critical
Unreviewed
CVE-2022-45406
was published
Dec 22, 2022
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This...
Critical
Unreviewed
CVE-2022-46882
was published
Dec 22, 2022
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is...
Critical
Unreviewed
CVE-2021-33640
was published
Dec 19, 2022
drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.
Critical
Unreviewed
CVE-2022-45474
was published
Nov 18, 2022
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory...
Critical
Unreviewed
CVE-2022-43286
was published
Oct 29, 2022
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the...
Critical
Unreviewed
CVE-2022-3649
was published
Oct 22, 2022
A vulnerability was found in Exim and classified as problematic. This issue affects the function...
Critical
Unreviewed
CVE-2022-3620
was published
Oct 21, 2022
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This...
Critical
Unreviewed
CVE-2022-0699
was published
Oct 17, 2022
The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this...
Critical
Unreviewed
CVE-2022-38983
was published
Oct 14, 2022
SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function...
Critical
Unreviewed
CVE-2022-40009
was published
Sep 21, 2022
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
Critical
Unreviewed
CVE-2022-40674
was published
Sep 15, 2022
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io()...
Critical
Unreviewed
CVE-2022-2526
was published
Sep 10, 2022
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190...
Critical
Unreviewed
CVE-2022-2738
was published
Sep 2, 2022
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes...
Critical
Unreviewed
CVE-2021-39815
was published
Aug 25, 2022
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes...
Critical
Unreviewed
CVE-2022-20122
was published
Aug 25, 2022
HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code...
Critical
Unreviewed
CVE-2022-38667
was published
Aug 23, 2022
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via...
Critical
Unreviewed
CVE-2022-35164
was published
Aug 19, 2022
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function...
Critical
Unreviewed
CVE-2022-36190
was published
Aug 18, 2022
Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to...
Critical
Unreviewed
CVE-2022-1853
was published
Jul 28, 2022
Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who...
Critical
Unreviewed
CVE-2022-1312
was published
Jul 26, 2022
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote...
Critical
Unreviewed
CVE-2022-0977
was published
Jul 22, 2022
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in...
Critical
Unreviewed
CVE-2022-32081
was published
Jul 2, 2022
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at ...
Critical
Unreviewed
CVE-2022-32091
was published
Jul 2, 2022
ProTip!
Advisories are also available from the
GraphQL API