GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
5,179 advisories
Filter by severity
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability...
High
Unreviewed
CVE-2026-85150
was published
Sep 3, 2026
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
Moderate
Unreviewed
CVE-2026-78126
was published
Sep 11, 2026
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute...
High
Unreviewed
CVE-2026-78130
was published
Sep 11, 2026
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler...
Moderate
Unreviewed
CVE-2026-86547
was published
Sep 9, 2026
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results...
High
Unreviewed
CVE-2026-18453
was published
Sep 7, 2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over...
Moderate
Unreviewed
CVE-2026-66303
was published
Sep 8, 2026
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an...
Moderate
Unreviewed
CVE-2026-28581
was published
Jun 2, 2026
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-77489
was published
Sep 8, 2026
Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2026-77901
was published
Sep 8, 2026
Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an...
High
Unreviewed
CVE-2026-72949
was published
Sep 8, 2026
Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a...
Moderate
Unreviewed
CVE-2026-70575
was published
Sep 8, 2026
Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized...
Moderate
Unreviewed
CVE-2026-72939
was published
Sep 8, 2026
Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over...
High
Unreviewed
CVE-2026-69744
was published
Sep 8, 2026
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service...
High
Unreviewed
CVE-2026-69881
was published
Sep 8, 2026
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service...
High
Unreviewed
CVE-2026-69587
was published
Sep 8, 2026
Null pointer dereference in Virtual Hard Disk (VHD) Miniport Driver allows an unauthorized...
High
Unreviewed
CVE-2026-69384
was published
Sep 8, 2026
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to...
Moderate
Unreviewed
CVE-2026-62762
was published
Sep 8, 2026
A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all...
Low
Unreviewed
CVE-2026-84392
was published
Sep 8, 2026
A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash...
High
Unreviewed
CVE-2026-82055
was published
Sep 8, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: use a stable...
Moderate
Unreviewed
CVE-2026-46086
was published
May 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
nexthop: fix IPv6 route...
Moderate
Unreviewed
CVE-2026-53012
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
net: Drop the lock in...
Moderate
Unreviewed
CVE-2026-43216
was published
May 6, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_osf:...
High
Unreviewed
CVE-2026-52998
was published
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_conntrack_sip:...
Critical
Unreviewed
CVE-2026-52986
was published
Jun 24, 2026
ProTip!
Advisories are also available from the
GraphQL API