GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
79 advisories
Filter by severity
alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap...
Moderate
Unreviewed
CVE-2026-25068
was published
Jan 29, 2026
cert-manager-controller DoS via Specially Crafted DNS Response
Moderate
CVE-2026-25518
was published
for
github.com/cert-manager/cert-manager
(Go)
Feb 2, 2026
Metricbeat affected by multiple denial of service vulnerabilities
Moderate
CVE-2026-0528
was published
for
github.com/elastic/beats/v7
(Go)
Jan 13, 2026
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an...
Moderate
Unreviewed
CVE-2026-0529
was published
Jan 14, 2026
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows...
Moderate
Unreviewed
CVE-2025-65499
was published
Nov 24, 2025
A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds...
Moderate
Unreviewed
CVE-2025-10158
was published
Nov 18, 2025
The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console...
Moderate
Unreviewed
CVE-2024-35164
was published
Jul 2, 2025
In the Linux kernel, the following vulnerability has been resolved:
clk: samsung: Fix UBSAN...
Moderate
Unreviewed
CVE-2025-39728
was published
Apr 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
net_sched: sch_sfq: don't...
Moderate
Unreviewed
CVE-2024-57996
was published
Feb 27, 2025
Improper validation of an array index in the AND power Management Firmware could allow a...
Moderate
Unreviewed
CVE-2024-21970
was published
Sep 6, 2025
Improper array index verification vulnerability in the audio codec module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54650
was published
Aug 6, 2025
Out-of-bounds array access issue due to insufficient data verification in the location service...
Moderate
Unreviewed
CVE-2025-54645
was published
Aug 6, 2025
Out-of-bounds access vulnerability in the audio codec module.
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2025-54610
was published
Aug 6, 2025
Memory corruption while operating the mailbox in Automotive.
Moderate
Unreviewed
CVE-2024-53009
was published
Jul 8, 2025
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x...
Moderate
Unreviewed
CVE-2022-42011
was published
Oct 10, 2022
O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.
Moderate
Unreviewed
CVE-2024-34047
was published
Apr 30, 2024
If array shift operations are not used, the Garbage Collector may have become confused about...
Moderate
Unreviewed
CVE-2022-31745
was published
Dec 22, 2022
In the Linux kernel, the following vulnerability has been resolved:
speakup: Fix sizeof() vs...
Moderate
Unreviewed
CVE-2024-38587
was published
Jun 19, 2024
In the Linux kernel, the following vulnerability has been resolved:
md: Don't suspend the array...
Moderate
Unreviewed
CVE-2024-26755
was published
Apr 3, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix UBSAN array...
Moderate
Unreviewed
CVE-2023-52819
was published
May 21, 2024
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: use...
Moderate
Unreviewed
CVE-2023-52768
was published
May 21, 2024
JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index,...
Moderate
Unreviewed
CVE-2024-41565
was published
Aug 28, 2024
onos-lib-go allows an index out-of-range panic
Moderate
CVE-2025-30077
was published
for
github.com/onosproject/onos-lib-go
(Go)
Mar 16, 2025
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to...
Moderate
Unreviewed
CVE-2005-0369
was published
May 1, 2022
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: gcc-ipq8074: fix...
Moderate
Unreviewed
CVE-2024-26969
was published
May 1, 2024
ProTip!
Advisories are also available from the
GraphQL API