GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,984
Erlang
39
GitHub Actions
38
Go
2,626
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
954
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
313 advisories
Filter by severity
Information disclosure while processing message from client with invalid payload.
Moderate
Unreviewed
CVE-2025-47362
was published
Nov 4, 2025
Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM...
High
Unreviewed
CVE-2025-47368
was published
Nov 4, 2025
Information disclosure while registering commands from clients with diag through diagHal.
Moderate
Unreviewed
CVE-2025-27064
was published
Nov 4, 2025
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
Moderate
Unreviewed
CVE-2025-60729
was published
Oct 24, 2025
Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2025-59192
was published
Oct 14, 2025
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose...
Moderate
Unreviewed
CVE-2025-55325
was published
Oct 14, 2025
Transient DOS while processing IOCTL call for image encoding.
Moderate
Unreviewed
CVE-2025-27049
was published
Oct 9, 2025
Information disclosure while processing batch command execution in Video driver.
Moderate
Unreviewed
CVE-2025-27045
was published
Oct 9, 2025
Transient DOS while processing video packets received from video firmware.
Moderate
Unreviewed
CVE-2025-27041
was published
Oct 9, 2025
Information disclosure when Video engine escape input data is less than expected minimum size.
Moderate
Unreviewed
CVE-2025-27036
was published
Sep 24, 2025
Information disclosure while decoding this RTP packet headers received by UE from the network...
High
Unreviewed
CVE-2025-21488
was published
Sep 24, 2025
Information disclosure while decoding RTP packet received by UE from the network, when payload...
High
Unreviewed
CVE-2025-21487
was published
Sep 24, 2025
information disclosure while invoking calibration data from user space to update firmware size.
Moderate
Unreviewed
CVE-2025-27030
was published
Sep 24, 2025
Information disclosure while running video usecase having rogue firmware.
Moderate
Unreviewed
CVE-2025-27033
was published
Sep 24, 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
High
Unreviewed
CVE-2025-47318
was published
Sep 24, 2025
Transient DOS while handling command data during power control processing.
High
Unreviewed
CVE-2025-47326
was published
Sep 24, 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and...
High
Unreviewed
CVE-2025-21484
was published
Sep 24, 2025
Transient DOS while processing power control requests with invalid antenna or stream values.
High
Unreviewed
CVE-2025-47328
was published
Sep 24, 2025
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
High
Unreviewed
CVE-2025-47317
was published
Sep 24, 2025
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries)...
Moderate
Unreviewed
CVE-2025-4582
was published
Sep 23, 2025
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2025-54901
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53797
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53796
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53798
was published
Sep 9, 2025
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due...
High
Unreviewed
CVE-2025-36855
was published
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API