GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,893 advisories
Filter by severity
A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library. This...
High
Unreviewed
CVE-2025-12863
was published
Nov 7, 2025
Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote...
High
Unreviewed
CVE-2025-11756
was published
Nov 7, 2025
A use-after-free issue was addressed with improved memory management. This issue is fixed in...
High
Unreviewed
CVE-2023-43000
was published
Nov 5, 2025
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client...
High
Unreviewed
CVE-2025-62230
was published
Oct 30, 2025
A flaw was found in the X.Org X server and Xwayland when processing X11 Present extension...
High
Unreviewed
CVE-2025-62229
was published
Oct 30, 2025
Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-11465
was published
Oct 29, 2025
A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc....
High
Unreviewed
CVE-2025-53814
was published
Oct 28, 2025
In the Linux kernel, the following vulnerability has been resolved:
tty: goldfish: Fix free_irq(...
High
Unreviewed
CVE-2022-49724
was published
Oct 24, 2025
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used...
High
Unreviewed
CVE-2025-12105
was published
Oct 23, 2025
In quickjs, in js_print_object, when printing an array, the function first fetches the array...
High
Unreviewed
CVE-2025-62490
was published
Oct 16, 2025
A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when...
High
Unreviewed
CVE-2025-62491
was published
Oct 16, 2025
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server,...
High
Unreviewed
CVE-2025-48008
was published
Oct 15, 2025
Animate versions 23.0.13, 24.0.10 and earlier are affected by a Use After Free vulnerability that...
High
Unreviewed
CVE-2025-54279
was published
Oct 15, 2025
Substance3D - Stager versions 3.1.4 and earlier are affected by a Use After Free vulnerability...
High
Unreviewed
CVE-2025-61802
was published
Oct 14, 2025
Dimension versions 4.1.4 and earlier are affected by a Use After Free vulnerability that could...
High
Unreviewed
CVE-2025-61801
was published
Oct 14, 2025
Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free...
High
Unreviewed
CVE-2025-54281
was published
Oct 14, 2025
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-59290
was published
Oct 14, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59236
was published
Oct 14, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59243
was published
Oct 14, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59234
was published
Oct 14, 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-59238
was published
Oct 14, 2025
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-59202
was published
Oct 14, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59227
was published
Oct 14, 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59222
was published
Oct 14, 2025
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-59226
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API