GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      542 advisories
        Filter by severity
        
      
      
    
                    
                      Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4174
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4173
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-3003
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-3001
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-7020
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-0983
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-39815
                      
                      was published
                      Aug 25, 2022 
                    
                  
                    
                      The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-20122
                      
                      was published
                      Aug 25, 2022 
                    
                  
                    
                      A use after free issue was addressed with improved memory management. This issue is fixed in tvOS...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-22641
                      
                      was published
                      Mar 19, 2022 
                    
                  
                    
                      use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-1106
                      
                      was published
                      Mar 28, 2022 
                    
                  
                    
                      Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0790
                      
                      was published
                      Apr 6, 2022 
                    
                  
                    
                      Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2....
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-1212
                      
                      was published
                      Apr 6, 2022 
                    
                  
                    
                      Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0452
                      
                      was published
                      Apr 6, 2022 
                    
                  
                    
                      nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-27007
                      
                      was published
                      Apr 15, 2022 
                    
                  
                    
                      An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-2891
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-2922
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-13224
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-5771
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6980
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-4263
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability....
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-11274
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6979
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6971
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6949
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-6964
                      
                      was published
                      May 17, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API