GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,367
Maven
5,000+
npm
3,986
NuGet
720
pip
3,778
Pub
12
RubyGems
926
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
91 advisories
Filter by severity
RISC Zero Ethereum invalid commitment with digest value of zero accepted by Steel.validateCommitment
Low
CVE-2025-52884
was published
for
risc0-ethereum-contracts
(Rust)
Jun 25, 2025
spytrap-adb Omission of Security-relevant Information
Low
CVE-2025-52926
was published
for
spytrap-adb
(Rust)
Jun 23, 2025
zkVM Underconstrained Vulnerability
Low
CVE-2025-52484
was published
for
risc0-circuit-rv32im
(Rust)
Jun 20, 2025
anon-vec lacks sufficient checks in public API
Low
GHSA-pr59-jjr4-gcf6
was published
for
anon-vec
(Rust)
Jun 5, 2025
process_lock has a Potential Unsound issue in unlock
Low
CVE-2025-48751
was published
for
process_lock
(Rust)
May 24, 2025
Process Sync has a Potential Unsound Issue in SharedMutex
Low
CVE-2025-48752
was published
for
process-sync
(Rust)
May 24, 2025
SCSIR has a Potential Unsound Issue in WriteSameCommand
Low
CVE-2025-48756
was published
for
scsir
(Rust)
May 24, 2025
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
Low
CVE-2025-46718
was published
for
sudo-rs
(Rust)
May 13, 2025
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
Low
CVE-2025-46717
was published
for
sudo-rs
(Rust)
May 13, 2025
libsql-sqlite3-parser crash due to invalid UTF-8 input
Low
CVE-2025-47736
was published
for
libsql-sqlite3-parser
(Rust)
May 9, 2025
trailer mishandles allocating with a size of zero
Low
CVE-2025-47737
was published
for
trailer
(Rust)
May 9, 2025
scanner has a Public API without sufficient bounds checking
Low
GHSA-79m9-55jc-p6mw
was published
for
scanner
(Rust)
May 7, 2025
Redox UEFI Safe API can cause heap-buffer-overflow
Low
GHSA-58xc-hpvq-8473
was published
for
redox_uefi_std
(Rust)
May 6, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
Low
GHSA-3824-qmfq-2qv7
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
Low
GHSA-2cvj-g5r5-jrrg
was published
for
surrealdb
(Rust)
Apr 10, 2025
Tokio broadcast channel calls clone in parallel, but does not require `Sync`
Low
GHSA-rr8g-9fpq-6wmg
was published
for
tokio
(Rust)
Apr 7, 2025
PyO3 Risk of buffer overflow in `PyString::from_object`
Low
GHSA-pph8-gcv7-4qj5
was published
for
pyo3
(Rust)
Apr 2, 2025
array-init-cursor is unsound when used with types that implement `Drop`
Low
GHSA-67r5-rqwv-9p9q
was published
for
array-init-cursor
(Rust)
Mar 31, 2025
tough cyclic delegation graphs are not detected
Low
GHSA-j8x2-777p-23fc
was published
for
tough
(Rust)
Mar 28, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
CVE-2025-27512
was published
for
zincati
(Rust)
Mar 17, 2025
Fyrox has unsound usages of `Vec::from_raw_parts`
Low
GHSA-h7h7-6mx3-r89v
was published
for
fyrox-core
(Rust)
Feb 14, 2025
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API