GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            266 advisories
        Filter by severity
        
      
      
    
                    
                      ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62594
                      
                      was published
                        for
                        
                          Magick.NET-Q16-HDRI-OpenMP-arm64
                        
                        (NuGet)
                      Oct 27, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom: bam_dma:...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49650
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
                    
                      
  Low
                    
                
                      
                        GHSA-h5j3-crg5-8jqm
                      
                      was published
                        for
                        
                          orx-pinned-vec
                        
                        (Rust)
                      Oct 21, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
RDMA/nldev: Prevent...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49199
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62495
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      In the Linux kernel, the following vulnerability has been resolved:
remoteproc: Fix count check...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-49278
                      
                      was published
                      Sep 22, 2025 
                    
                  
                    
                      NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-23335
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      The Honeywell Experion PKS contains an Integer Underflow 
vulnerability 
in the component...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3947
                      
                      was published
                      Jul 10, 2025 
                    
                  
                    
                      The Honeywell Experion PKS 
 and OneWireless WDM 
contains an Integer Underflow 
vulnerability...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2523
                      
                      was published
                      Jul 10, 2025 
                    
                  
                    
                      Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47130
                      
                      was published
                      Jul 9, 2025 
                    
                  
                    
                      InCopy versions 20.3, 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47097
                      
                      was published
                      Jul 9, 2025 
                    
                  
                    
                      Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47128
                      
                      was published
                      Jul 9, 2025 
                    
                  
                    
                      InDesign Desktop versions 19.5.3 and earlier are affected by an Integer Underflow (Wrap or...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47136
                      
                      was published
                      Jul 9, 2025 
                    
                  
                    
                      Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Underflow (Wrap or...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49532
                      
                      was published
                      Jul 9, 2025 
                    
                  
                    
                      An integer underflow in the image processing binary of the MIB3 infotainment unit allows an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-28902
                      
                      was published
                      Jun 28, 2025 
                    
                  
                    
                      IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-1991
                      
                      was published
                      Jun 28, 2025 
                    
                  
                    
                      An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-54028
                      
                      was published
                      Jun 2, 2025 
                    
                  
                    
                      setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49112
                      
                      was published
                      Jun 2, 2025 
                    
                  
                    
                      A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4948
                      
                      was published
                      May 19, 2025 
                    
                  
                    
                      Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30668
                      
                      was published
                      May 14, 2025 
                    
                  
                    
                      Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30324
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43546
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43555
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-29974
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47256
                      
                      was published
                      May 6, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API