GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      2,338 advisories
        Filter by severity
        
      
      
    
                    
                      Memory corruption while processing large input data from a remote source via a communication...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47365
                      
                      was published
                      Nov 4, 2025 
                    
                  
                    
                      Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12501
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62231
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10924
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10923
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11463
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      Integer Overflow vulnerability in SQLite SQLite3 v.3.50.0 allows a remote attacker to cause a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52099
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55067
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: dwc-qos:...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49642
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: validate BOOT...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49553
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62496
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61803
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61807
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Dimension versions 4.1.4 and earlier are affected by an Integer Overflow or Wraparound...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61800
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58715
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      In gnss driver, there is a possible out of bounds read due to an integer overflow. This could...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20722
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20710
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Memory corruption while processing user buffers.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47351
                      
                      was published
                      Oct 9, 2025 
                    
                  
                    
                      This vulnerability affects Firefox < 143.0.3.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11152
                      
                      was published
                      Sep 30, 2025 
                    
                  
                    
                      An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-51495
                      
                      was published
                      Sep 29, 2025 
                    
                  
                    
                      pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55552
                      
                      was published
                      Sep 25, 2025 
                    
                  
                    
                      pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55554
                      
                      was published
                      Sep 25, 2025 
                    
                  
                    
                      Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10892
                      
                      was published
                      Sep 24, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix qgroup reserve...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49075
                      
                      was published
                      Sep 23, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
af_netlink: Fix shift out of...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49197
                      
                      was published
                      Sep 23, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API