GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
7,722 advisories
Filter by severity
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially...
High
Unreviewed
CVE-2026-12927
was published
Jul 29, 2026
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32...
High
Unreviewed
CVE-2026-18220
was published
Jul 29, 2026
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie...
High
Unreviewed
CVE-2026-58184
was published
Jul 29, 2026
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
...
High
Unreviewed
CVE-2026-58188
was published
Jul 29, 2026
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use...
High
Unreviewed
CVE-2026-58177
was published
Jul 29, 2026
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated...
High
Unreviewed
CVE-2026-35226
was published
Jul 29, 2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of...
High
Unreviewed
CVE-2026-15057
was published
Jul 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48394
was published
Jul 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48392
was published
Jul 28, 2026
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code...
High
Unreviewed
CVE-2026-48393
was published
Jul 28, 2026
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
High
CVE-2026-32203
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 28, 2026
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to...
High
Unreviewed
CVE-2026-21047
was published
Jul 28, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in...
High
Unreviewed
CVE-2026-64764
was published
Jul 27, 2026
An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed...
High
Unreviewed
CVE-2026-64763
was published
Jul 27, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in...
High
Unreviewed
CVE-2026-64725
was published
Jul 27, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in...
High
Unreviewed
CVE-2026-64739
was published
Jul 27, 2026
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
High
Unreviewed
CVE-2026-66041
was published
Jul 24, 2026
Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker...
High
Unreviewed
CVE-2026-16807
was published
Jul 24, 2026
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video...
High
Unreviewed
CVE-2026-65703
was published
Jul 23, 2026
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX...
High
Unreviewed
CVE-2026-64835
was published
Jul 22, 2026
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker...
High
Unreviewed
CVE-2026-16413
was published
Jul 22, 2026
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
High
CVE-2026-59205
was published
for
pillow
(pip)
Jul 20, 2026
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
High
CVE-2026-59199
was published
for
Pillow
(pip)
Jul 20, 2026
Composer: Arbitrary file write outside vendor via malicious transitive package name
High
CVE-2026-59948
was published
for
composer/composer
(Composer)
Jul 20, 2026
In the Linux kernel, the following vulnerability has been resolved:
media: rzv2h-ivc: Fix...
High
Unreviewed
CVE-2026-53380
was published
Jul 19, 2026
ProTip!
Advisories are also available from the
GraphQL API