GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
313 advisories
Filter by severity
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet...
High
Unreviewed
CVE-2025-21427
was published
Jul 8, 2025
Memory corruption during the image encoding process.
High
Unreviewed
CVE-2025-27055
was published
Jul 8, 2025
Transient DOS while handling beacon frames with invalid IE header length.
High
Unreviewed
CVE-2025-27057
was published
Jul 8, 2025
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-47971
was published
Jul 8, 2025
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-47973
was published
Jul 8, 2025
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2025-49659
was published
Jul 8, 2025
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information...
Moderate
Unreviewed
CVE-2025-49684
was published
Jul 8, 2025
Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
Moderate
Unreviewed
CVE-2025-7745
was published
Jul 25, 2025
Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read
Moderate
GHSA-gw89-822v-8v8g
was published
for
openssl
(Rust)
Jul 28, 2025
•
withdrawn
Transient DOS while processing a frame with malformed shared-key descriptor.
High
Unreviewed
CVE-2025-27065
was published
Aug 6, 2025
Information disclosure while opening a fastrpc session when domain is not sanitized.
Moderate
Unreviewed
CVE-2025-21457
was published
Aug 6, 2025
Memory corruption while processing an IOCTL command with an arbitrary address.
High
Unreviewed
CVE-2025-27068
was published
Aug 6, 2025
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information...
Moderate
Unreviewed
CVE-2025-53736
was published
Aug 12, 2025
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due...
High
Unreviewed
CVE-2025-36855
was published
Sep 8, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53797
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53798
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53796
was published
Sep 9, 2025
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2025-54901
was published
Sep 9, 2025
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries)...
Moderate
Unreviewed
CVE-2025-4582
was published
Sep 23, 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
High
Unreviewed
CVE-2025-47318
was published
Sep 24, 2025
information disclosure while invoking calibration data from user space to update firmware size.
Moderate
Unreviewed
CVE-2025-27030
was published
Sep 24, 2025
Information disclosure while running video usecase having rogue firmware.
Moderate
Unreviewed
CVE-2025-27033
was published
Sep 24, 2025
Information disclosure while decoding this RTP packet headers received by UE from the network...
High
Unreviewed
CVE-2025-21488
was published
Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload...
High
Unreviewed
CVE-2025-21487
was published
Sep 24, 2025
Information disclosure when Video engine escape input data is less than expected minimum size.
Moderate
Unreviewed
CVE-2025-27036
was published
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API