GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
57
GitHub Actions
50
Go
3,767
Maven
5,000+
npm
5,000+
NuGet
937
pip
4,999
Pub
13
RubyGems
1,058
Rust
1,347
Swift
54
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Improper Synchronization in Jenkins Convertigo Mobile Platform Plugin
Low
CVE-2022-25210
was published
for
com.convertigo.jenkins.plugins:convertigo-mobile-platform
(Maven)
Feb 16, 2022
Delegate functions are missing `Send` bound
Critical
GHSA-x4mq-m75f-mx8m
was published
for
windows
(Rust)
Jun 17, 2022
Grafana Missing Synchronization vulnerability
High
CVE-2023-2801
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot...
High
Unreviewed
CVE-2023-45084
was published
Dec 5, 2023
A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks...
Moderate
Unreviewed
CVE-2024-30387
was published
Apr 12, 2024
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49114
was published
Dec 12, 2024
A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the...
High
Unreviewed
CVE-2025-1445
was published
Mar 25, 2025
LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list...
Critical
Unreviewed
CVE-2025-47154
was published
May 1, 2025
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an...
Moderate
Unreviewed
CVE-2025-47999
was published
Jul 8, 2025
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an...
Moderate
Unreviewed
CVE-2025-49751
was published
Aug 12, 2025
The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online...
High
Unreviewed
CVE-2022-50238
was published
Sep 8, 2025
Requires malware code to misuse the DDK kernel module IOCTL interface.
Such code can use the...
High
Unreviewed
CVE-2026-22163
was published
Mar 21, 2026
free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
Moderate
CVE-2026-44318
was published
for
github.com/free5gc/bsf
(Go)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API