GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
709 advisories
Filter by severity
In isp, there is a possible out of bounds write due to a race condition. This could lead to local...
Moderate
Unreviewed
CVE-2022-32638
was published
Jan 3, 2023
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka ...
Low
Unreviewed
CVE-2018-0966
was published
May 13, 2022
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced...
High
Unreviewed
CVE-2018-8584
was published
May 13, 2022
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka ...
Low
Unreviewed
CVE-2018-8449
was published
May 13, 2022
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd...
Moderate
Unreviewed
CVE-2022-22220
was published
Oct 18, 2022
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon ...
Moderate
Unreviewed
CVE-2022-22225
was published
Oct 18, 2022
Memory corruption in display due to time-of-check time-of-use of metadata reserved size in...
High
Unreviewed
CVE-2022-33214
was published
Oct 19, 2022
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection...
High
Unreviewed
CVE-2022-41744
was published
Oct 11, 2022
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB...
High
Unreviewed
CVE-2022-30283
was published
Nov 16, 2022
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all...
Moderate
Unreviewed
CVE-2022-23029
was published
Jan 26, 2022
VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way...
High
Unreviewed
CVE-2021-22043
was published
Feb 17, 2022
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race...
High
Unreviewed
CVE-2022-24335
was published
Feb 26, 2022
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Low
Unreviewed
CVE-2013-4235
was published
May 5, 2022
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in...
Moderate
Unreviewed
CVE-2018-16872
was published
May 13, 2022
DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI...
Moderate
Unreviewed
CVE-2022-33906
was published
Nov 15, 2022
DMA transactions which are targeted at input buffers used for the software SMI handler used by...
Moderate
Unreviewed
CVE-2022-33907
was published
Nov 15, 2022
DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI...
High
Unreviewed
CVE-2022-33984
was published
Nov 15, 2022
Update description and links DMA transactions which are targeted at input buffers used for the...
Moderate
Unreviewed
CVE-2022-31243
was published
Nov 15, 2022
DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after...
Moderate
Unreviewed
CVE-2022-30774
was published
Nov 15, 2022
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS...
High
Unreviewed
CVE-2022-27538
was published
Feb 1, 2023
Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious...
High
Unreviewed
CVE-2022-34398
was published
Feb 1, 2023
DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead...
Moderate
Unreviewed
CVE-2022-33982
was published
Nov 15, 2022
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the...
High
Unreviewed
CVE-2022-32476
was published
Feb 15, 2023
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the...
High
Unreviewed
CVE-2022-32470
was published
Feb 15, 2023
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the...
High
Unreviewed
CVE-2022-32475
was published
Feb 15, 2023
ProTip!
Advisories are also available from the
GraphQL API