GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
111 advisories
Filter by severity
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and...
Moderate
Unreviewed
CVE-2025-65519
was published
Feb 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
rcu: Avoid stack overflow...
Moderate
Unreviewed
CVE-2023-53655
was published
Oct 7, 2025
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12...
Moderate
Unreviewed
CVE-2025-36001
was published
Jan 31, 2026
In the Linux kernel, the following vulnerability has been resolved:
nbd: fix incomplete...
Moderate
Unreviewed
CVE-2023-53513
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
block: avoid possible...
Moderate
Unreviewed
CVE-2025-39795
was published
Sep 12, 2025
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability...
Moderate
Unreviewed
CVE-2026-0990
was published
Jan 15, 2026
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: Fix semi...
Moderate
Unreviewed
CVE-2025-38614
was published
Aug 19, 2025
In the Linux kernel, the following vulnerability has been resolved:
powercap: arm_scmi: Remove...
Moderate
Unreviewed
CVE-2023-53428
was published
Sep 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm -...
Moderate
Unreviewed
CVE-2022-50407
was published
Sep 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Fix stack...
Moderate
Unreviewed
CVE-2025-39704
was published
Sep 5, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain...
Moderate
Unreviewed
CVE-2025-36158
was published
Nov 21, 2025
In the Linux kernel, the following vulnerability has been resolved:
tracing/osnoise: Fix crash...
Moderate
Unreviewed
CVE-2025-38493
was published
Jul 28, 2025
In the Linux kernel, the following vulnerability has been resolved:
powerpc/perf: Optimize...
Moderate
Unreviewed
CVE-2022-50118
was published
Jun 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintel: Check...
Moderate
Unreviewed
CVE-2025-38315
was published
Jul 10, 2025
In the Linux kernel, the following vulnerability has been resolved:
fbdev: omapfb: Add 'plane'...
Moderate
Unreviewed
CVE-2025-37851
was published
May 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
perf: Improve missing...
Moderate
Unreviewed
CVE-2022-49782
was published
May 1, 2025
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows...
Moderate
Unreviewed
CVE-2019-6285
was published
May 13, 2022
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a...
Moderate
Unreviewed
CVE-2025-9714
was published
Sep 10, 2025
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Check for any...
Moderate
Unreviewed
CVE-2023-52986
was published
Mar 27, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an...
Moderate
Unreviewed
CVE-2025-33096
was published
Oct 12, 2025
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply...
Moderate
Unreviewed
CVE-2025-43718
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
riscv: VMAP_STACK overflow...
Moderate
Unreviewed
CVE-2023-52761
was published
May 21, 2024
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
Moderate
Unreviewed
CVE-2025-24302
was published
Aug 12, 2025
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
Moderate
Unreviewed
CVE-2025-20025
was published
Aug 12, 2025
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via...
Moderate
Unreviewed
CVE-2022-25313
was published
Feb 19, 2022
ProTip!
Advisories are also available from the
GraphQL API