GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,297
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
920
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
708 advisories
Filter by severity
Chakra Scripting Engine RCE via Out-of-bounds write
High
CVE-2019-1052
was published
for
Microsoft.ChakraCore
(NuGet)
May 24, 2022
Chakra Scripting Engine RCE via Out-of-bounds write
High
CVE-2019-1051
was published
for
Microsoft.ChakraCore
(NuGet)
May 24, 2022
Chakra Scripting Engine RCE Vulnerability
High
CVE-2019-1024
was published
for
Microsoft.ChakraCore
(NuGet)
May 24, 2022
Chakra Scripting Engine Out-of-bounds write
High
CVE-2019-1003
was published
for
Microsoft.ChakraCore
(NuGet)
Mar 29, 2021
ChakraCore RCE via Out-of-bounds write
High
CVE-2019-1002
was published
for
Microsoft.ChakraCore
(NuGet)
May 24, 2022
Chakra Scripting Engine Out-of-bounds write
High
CVE-2019-0993
was published
for
Microsoft.ChakraCore
(NuGet)
Mar 29, 2021
Chakra Scripting Engine Out-of-bounds write
High
CVE-2019-0992
was published
for
Microsoft.ChakraCore
(NuGet)
Mar 29, 2021
Chakra Scripting Engine Out-of-bounds write
High
CVE-2019-0991
was published
for
Microsoft.ChakraCore
(NuGet)
Mar 29, 2021
Chakra Scripting Engine Memory Corruption Vulnerability
High
CVE-2019-0989
was published
for
Microsoft.ChakraCore
(NuGet)
Mar 29, 2021
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
High
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
libwebp: OOB write in BuildHuffmanTable
High
CVE-2023-4863
was published
for
Pillow
(Go)
Sep 12, 2023
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
CVE-2025-47280
was published
for
Umbraco.Forms
(NuGet)
May 13, 2025
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Moderate
CVE-2025-46736
was published
for
Umbraco.Cms
(NuGet)
May 6, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21176
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21172
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2024-38229 | .NET Remote Code Execution Vulnerability
High
CVE-2024-38229
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Oct 8, 2024
Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability
Critical
CVE-2024-35264
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Jul 9, 2024
DotNetZip Zip-Slip Vulnerability
Moderate
CVE-2018-1002205
was published
for
DotNetZip
(NuGet)
Oct 16, 2018
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46326
was published
for
Snowflake.Data
(NuGet)
Apr 28, 2025
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-29953
was published
for
Apache.NMS.ActiveMQ
(NuGet)
Apr 18, 2025
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes
Moderate
CVE-2025-24011
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6531
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
ProTip!
Advisories are also available from the
GraphQL API