GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
32 advisories
Filter by severity
Improper null termination vulnerability in TUBITAK BILGEM Software Technologies Research...
Low
Unreviewed
CVE-2026-12386
was published
Jul 5, 2026
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs.
...
Critical
Unreviewed
CVE-2026-8721
was published
May 17, 2026
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared...
High
Unreviewed
CVE-2026-42010
was published
May 7, 2026
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string...
Low
Unreviewed
CVE-2026-2239
was published
Mar 26, 2026
miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV...
Moderate
Unreviewed
CVE-2026-32837
was published
Mar 17, 2026
Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of...
Low
Unreviewed
CVE-2026-23749
was published
Feb 26, 2026
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026)...
High
Unreviewed
CVE-2025-2026
was published
Dec 31, 2025
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1...
High
Unreviewed
CVE-2025-67790
was published
Dec 17, 2025
Envoy's TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Moderate
CVE-2025-66220
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
Moderate
CVE-2025-61912
was published
for
python-ldap
(pip)
Oct 10, 2025
Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid ...
Moderate
Unreviewed
CVE-2024-31197
was published
Sep 18, 2024
Microsoft SQL Server Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-43474
was published
Sep 10, 2024
A missing null-termination character in the last element of an nvlist array string can lead to...
High
Unreviewed
CVE-2024-45288
was published
Sep 5, 2024
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16...
High
Unreviewed
CVE-2024-31484
was published
May 14, 2024
Windows USB Print Driver Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-21442
was published
Mar 12, 2024
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user...
Moderate
Unreviewed
CVE-2023-48674
was published
Mar 1, 2024
In ModSecurity before 2.9.7, FILES_TMP_CONTENT sometimes lacked the complete content. This can...
Critical
Unreviewed
CVE-2023-24021
was published
Jan 20, 2023
An issue was discovered in drachtio-server before 0.8.20. It allows remote attackers to cause a...
High
Unreviewed
CVE-2022-47515
was published
Dec 18, 2022
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC)...
High
Unreviewed
CVE-2021-31887
was published
May 24, 2022
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC)...
Critical
Unreviewed
CVE-2021-31886
was published
May 24, 2022
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC)...
High
Unreviewed
CVE-2021-31888
was published
May 24, 2022
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC)...
Critical
Unreviewed
CVE-2021-31884
was published
May 24, 2022
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS,...
Critical
Unreviewed
CVE-2021-22931
was published
May 24, 2022
A vulnerability has been identified in Nucleus 4 (All versions < V4.1.0), Nucleus NET (All...
Moderate
Unreviewed
CVE-2020-27736
was published
May 24, 2022
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber...
High
Unreviewed
CVE-2021-1469
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API