GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
340 advisories
Filter by severity
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker...
Critical
Unreviewed
CVE-2024-41787
was published
Jan 10, 2025
In the Linux kernel, the following vulnerability has been resolved:
HID: logitech-hidpp: Fix...
Moderate
Unreviewed
CVE-2023-52478
was published
Feb 29, 2024
APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by...
High
Unreviewed
CVE-2024-42444
was published
Jan 14, 2025
Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU)...
Moderate
Unreviewed
CVE-2025-22394
was published
Jan 15, 2025
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before...
Low
Unreviewed
CVE-2024-37181
was published
Jan 16, 2025
Waitress has request processing race condition in HTTP pipelining with invalid first request
Critical
CVE-2024-49768
was published
for
waitress
(pip)
Oct 29, 2024
Apache StreamPipes potentially allows creation of multiple identical accounts
Moderate
CVE-2024-30471
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
WordOps has TOCTOU race condition
Moderate
CVE-2024-34528
was published
for
wordops
(pip)
May 6, 2024
ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox Escape
High
GHSA-vp47-9734-prjw
was published
for
asteval
(pip)
Jan 23, 2025
An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI...
High
Unreviewed
CVE-2024-1563
was published
Feb 22, 2024
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password...
High
Unreviewed
CVE-2024-39894
was published
Jul 2, 2024
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the...
Moderate
Unreviewed
CVE-2022-38730
was published
Apr 27, 2023
Memory corruption while parsing the memory map info in IOCTL calls.
High
Unreviewed
CVE-2024-38418
was published
Feb 3, 2025
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
High
Unreviewed
CVE-2024-45560
was published
Feb 3, 2025
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the...
High
Unreviewed
CVE-2024-48394
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API