GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,585
Maven
5,000+
npm
5,000+
NuGet
923
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
107 advisories
Filter by severity
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in...
High
Unreviewed
CVE-2026-6751
was published
Apr 21, 2026
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in...
Critical
Unreviewed
CVE-2026-6748
was published
Apr 21, 2026
Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a...
High
Unreviewed
CVE-2026-6311
was published
Apr 15, 2026
Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5888
was published
Apr 9, 2026
An authenticated user with the read role may read limited amounts of uninitialized stack memory...
High
Unreviewed
CVE-2026-4147
was published
Mar 17, 2026
OpenEXR Makes Use of Uninitialized Memory
Low
CVE-2025-64181
was published
for
OpenEXR
(pip)
Apr 6, 2026
Uninitialized Variable in fastecdsa
High
CVE-2024-21502
was published
for
fastecdsa
(pip)
Feb 24, 2024
Helm's Missing YAML Content Leads To Panic
High
CVE-2024-26147
was published
for
helm.sh/helm/v3
(Go)
Feb 22, 2024
A maliciously crafted STP or SLDPRT file when ODXSW_DLL.dll parsed through Autodesk AutoCAD can...
High
Unreviewed
CVE-2024-23137
was published
Feb 22, 2024
Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148.
Critical
Unreviewed
CVE-2026-2806
was published
Feb 24, 2026
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus...
High
Unreviewed
CVE-2026-20051
was published
Feb 25, 2026
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in...
High
Unreviewed
CVE-2026-1333
was published
Feb 16, 2026
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating...
Low
Unreviewed
CVE-2025-58466
was published
Feb 11, 2026
Improper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow...
Moderate
Unreviewed
CVE-2025-29952
was published
Feb 10, 2026
Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor...
Moderate
Unreviewed
CVE-2025-32467
was published
Feb 10, 2026
Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service...
Moderate
Unreviewed
CVE-2026-22188
was published
Jan 7, 2026
Memory corruption while processing identity credential operations in the trusted application.
High
Unreviewed
CVE-2025-47348
was published
Jan 7, 2026
In display, there is a possible memory corruption due to uninitialized data. This could lead to...
Moderate
Unreviewed
CVE-2025-20784
was published
Jan 6, 2026
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to...
High
Unreviewed
CVE-2025-36935
was published
Dec 11, 2025
A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static...
High
Unreviewed
CVE-2025-10021
was published
Dec 22, 2025
In display, there is a possible memory corruption due to improper input validation. This could...
High
Unreviewed
CVE-2025-20766
was published
Dec 2, 2025
In display, there is a possible escalation of privilege due to improper input validation. This...
Moderate
Unreviewed
CVE-2025-20771
was published
Dec 2, 2025
A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications,...
High
Unreviewed
CVE-2024-37002
was published
Jun 25, 2024
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537...
High
Unreviewed
CVE-2023-31275
was published
Nov 27, 2023
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther...
Moderate
Unreviewed
CVE-2023-31192
was published
Oct 12, 2023
ProTip!
Advisories are also available from the
GraphQL API