GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
2,426 advisories
Filter by severity
A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to...
Moderate
Unreviewed
CVE-2025-0704
was published
Jan 24, 2025
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a...
Moderate
Unreviewed
CVE-2023-20930
was published
May 16, 2023
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access...
High
Unreviewed
CVE-2023-21110
was published
May 16, 2023
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
Moderate
CVE-2024-10846
was published
for
github.com/compose-spec/compose-go/v2
(Go)
Jan 21, 2025
Apache Wicket: An attacker can intentionally trigger a memory leak
Critical
CVE-2024-53299
was published
for
org.apache.wicket:wicket-core
(Maven)
Jan 23, 2025
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
go-git clients vulnerable to DoS via maliciously crafted Git server replies
High
CVE-2025-21614
was published
for
github.com/go-git/go-git
(Go)
Jan 6, 2025
Apache CXF: Denial of Service vulnerability with temporary files
Moderate
CVE-2025-23184
was published
for
org.apache.cxf:cxf-core
(Maven)
Jan 21, 2025
REXML denial of service vulnerability
Moderate
CVE-2024-39908
was published
for
rexml
(RubyGems)
Jul 16, 2024
Withdrawn Advisory: Netty vulnerability included in redis lettuce
Moderate
GHSA-q4h9-7rxj-7gx2
was published
for
io.lettuce:lettuce-core
(Maven)
Dec 2, 2024
•
withdrawn
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially...
High
Unreviewed
CVE-2019-9517
was published
May 24, 2022
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a...
High
Unreviewed
CVE-2019-9518
was published
May 24, 2022
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of...
High
Unreviewed
CVE-2019-9513
was published
May 24, 2022
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of...
Moderate
Unreviewed
CVE-2019-9516
was published
May 24, 2022
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial...
High
Unreviewed
CVE-2019-9515
was published
May 24, 2022
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
Moderate
Unreviewed
CVE-2023-33720
was published
May 26, 2023
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization...
High
Unreviewed
CVE-2019-9511
was published
May 24, 2022
Windows upnphost.dll Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21389
was published
Jan 14, 2025
Windows Remote Desktop Services Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21330
was published
Jan 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21289
was published
Jan 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21270
was published
Jan 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21290
was published
Jan 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21251
was published
Jan 14, 2025
Windows upnphost.dll Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21300
was published
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API