GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,055 advisories
Filter by severity
A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to...
Moderate
Unreviewed
CVE-2025-0704
was published
Jan 24, 2025
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a...
Moderate
Unreviewed
CVE-2023-20930
was published
May 16, 2023
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
Moderate
CVE-2024-10846
was published
for
github.com/compose-spec/compose-go/v2
(Go)
Jan 21, 2025
Apache CXF: Denial of Service vulnerability with temporary files
Moderate
CVE-2025-23184
was published
for
org.apache.cxf:cxf-core
(Maven)
Jan 21, 2025
REXML denial of service vulnerability
Moderate
CVE-2024-39908
was published
for
rexml
(RubyGems)
Jul 16, 2024
Withdrawn Advisory: Netty vulnerability included in redis lettuce
Moderate
GHSA-q4h9-7rxj-7gx2
was published
for
io.lettuce:lettuce-core
(Maven)
Dec 2, 2024
•
withdrawn
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of...
Moderate
Unreviewed
CVE-2019-9516
was published
May 24, 2022
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
Moderate
Unreviewed
CVE-2023-33720
was published
May 26, 2023
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly...
Moderate
Unreviewed
CVE-2023-0616
was published
Jun 2, 2023
Mattermost denial of service through long emoji value
Moderate
CVE-2024-24988
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 29, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource...
Moderate
Unreviewed
CVE-2024-47239
was published
Jan 8, 2025
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent...
Moderate
Unreviewed
CVE-2023-29767
was published
Jun 9, 2023
Werkzeug possible resource exhaustion when parsing file data in forms
Moderate
CVE-2024-49767
was published
for
Quart
(pip)
Oct 25, 2024
Windows Event Logging Service Denial of Service Vulnerability.
Moderate
Unreviewed
CVE-2022-37981
was published
Oct 12, 2022
Windows Kernel Denial of Service Vulnerability.
Moderate
Unreviewed
CVE-2022-30155
was published
Jun 16, 2022
Windows WLAN AutoConfig Service Denial of Service Vulnerability.
Moderate
Unreviewed
CVE-2022-29121
was published
May 11, 2022
Windows Hyper-V Denial of Service Vulnerability.
Moderate
Unreviewed
CVE-2022-22713
was published
May 11, 2022
CWA-2023-004: Excessive number of function parameters in compiled Wasm
Moderate
GHSA-75qh-gg76-p2w4
was published
for
cosmwasm-vm
(Go)
Aug 27, 2024
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP...
Moderate
Unreviewed
CVE-2022-27600
was published
Dec 19, 2024
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Dec 17, 2024
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability ...
Moderate
Unreviewed
CVE-2024-12698
was published
Dec 18, 2024
fetch(url) leads to a memory leak in undici
Moderate
CVE-2024-24750
was published
for
undici
(npm)
Feb 16, 2024
ProTip!
Advisories are also available from the
GraphQL API