GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
319 advisories
Filter by severity
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a...
Moderate
Unreviewed
CVE-2022-3590
was published
Dec 14, 2022
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows...
Moderate
Unreviewed
CVE-2017-11830
was published
May 13, 2022
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious...
High
Unreviewed
CVE-2017-0412
was published
May 13, 2022
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious...
High
Unreviewed
CVE-2017-0411
was published
May 13, 2022
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused...
High
Unreviewed
CVE-2022-22753
was published
Dec 22, 2022
When installing an add-on, Firefox verified the signature before prompting the user; but while...
High
Unreviewed
CVE-2022-26387
was published
Dec 22, 2022
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability...
High
Unreviewed
CVE-2025-23359
was published
Feb 12, 2025
In the Linux kernel, the following vulnerability has been resolved:
firmware: qcom: uefisecapp:...
Moderate
Unreviewed
CVE-2025-21998
was published
Apr 3, 2025
MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.
High
Unreviewed
CVE-2025-27812
was published
Apr 10, 2025
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA)...
High
Unreviewed
CVE-2025-21191
was published
Apr 8, 2025
Information disclosure may be there when a guest VM is connected.
Moderate
Unreviewed
CVE-2025-21431
was published
Apr 7, 2025
Memory corruption occurs during the copying of read data from the EEPROM because the IO...
High
Unreviewed
CVE-2024-43067
was published
Apr 7, 2025
A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user...
High
Unreviewed
CVE-2022-48191
was published
Jan 20, 2023
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can...
Moderate
Unreviewed
CVE-2024-7531
was published
Aug 6, 2024
APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use ...
High
Unreviewed
CVE-2024-54084
was published
Mar 11, 2025
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect...
High
Unreviewed
CVE-2024-53694
was published
Mar 7, 2025
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that...
Critical
Unreviewed
CVE-2025-22224
was published
Mar 4, 2025
Memory corruption may occur while processing message from frontend during allocation.
High
Unreviewed
CVE-2024-53028
was published
Mar 3, 2025
Memory corruption may occur in keyboard virtual device due to guest VM interaction.
High
Unreviewed
CVE-2024-53032
was published
Mar 3, 2025
IBM EntireX 11.1 could allow a local user to unintentionally modify data timestamp integrity due...
Low
Unreviewed
CVE-2025-0759
was published
Feb 27, 2025
Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software...
Moderate
Unreviewed
CVE-2024-41917
was published
Feb 13, 2025
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-24036
was published
Feb 11, 2025
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the...
High
Unreviewed
CVE-2024-48394
was published
Feb 6, 2025
Memory corruption while parsing the memory map info in IOCTL calls.
High
Unreviewed
CVE-2024-38418
was published
Feb 3, 2025
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.
High
Unreviewed
CVE-2024-45560
was published
Feb 3, 2025
ProTip!
Advisories are also available from the
GraphQL API