GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,950
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,603
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,250
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      755
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,013
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,048
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      5,347 advisories
        Filter by severity
        
      
      
    
                    
                      In the Linux kernel, the following vulnerability has been resolved:
tty: goldfish: Fix free_irq(...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49724
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      A flaw was found in the asynchronous message queue handling of the libsoup library, widely used...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12105
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2015-0313
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-1776
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-0322
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2012-4792
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2012-4969
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2010-3962
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2009-4324
                      
                      was published
                      May 2, 2022 
                    
                  
                    
                      Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-8439
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-0496
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2013-2551
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2013-1347
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2013-3897
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2013-3893
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27038
                      
                      was published
                      Jun 3, 2025 
                    
                  
                    
                      Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32709
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-29824
                      
                      was published
                      Apr 8, 2025 
                    
                  
                    
                      Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30400
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      An attacker was able to achieve code execution in the content process by exploiting a use-after...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-9680
                      
                      was published
                      Oct 9, 2024 
                    
                  
                    
                      Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38193
                      
                      was published
                      Aug 13, 2024 
                    
                  
                    
                      Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-4671
                      
                      was published
                      May 14, 2024 
                    
                  
                    
                      Memory corruption in DSP Services during a remote call from HLOS to DSP.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-33063
                      
                      was published
                      Dec 5, 2023 
                    
                  
                    
                      Memory corruption while submitting a large list of sync points in an AUX command to the...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-33106
                      
                      was published
                      Dec 5, 2023 
                    
                  
                    
                      Possible use after free when process shell memory is freed using IOCTL munmap call and process...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-22071
                      
                      was published
                      Jun 15, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API