GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
76 advisories
Filter by severity
Rack has possible DoS Vulnerability with Range Header
Low
CVE-2024-26141
was published
for
rack
(RubyGems)
Feb 28, 2024
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform...
Low
Unreviewed
CVE-2023-49578
was published
Dec 12, 2023
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background...
Low
Unreviewed
CVE-2023-5870
was published
Dec 10, 2023
eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations
Low
GHSA-v7hc-87jc-qrrr
was published
for
knative.dev/eventing-github
(Go)
Dec 6, 2023
Cosign vulnerable to possible endless data attack from attacker-controlled registry
Low
CVE-2023-46737
was published
for
github.com/sigstore/cosign
(Go)
Nov 8, 2023
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an...
Low
Unreviewed
CVE-2023-5876
was published
Nov 2, 2023
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this...
Low
Unreviewed
CVE-2023-41310
was published
Sep 27, 2023
Denial of service from large image
Low
CVE-2023-37900
was published
for
github.com/crossplane/crossplane
(Go)
Jul 28, 2023
Fides Webserver Vulnerable to SVG Bomb File Uploads
Low
CVE-2023-37481
was published
for
ethyca-fides
(pip)
Jul 18, 2023
Fides Webserver Vulnerable to Zip Bomb File Uploads
Low
CVE-2023-37480
was published
for
ethyca-fides
(pip)
Jul 18, 2023
Mattermost fails to properly validate a gif image file, allowing an attacker to consume a...
Low
Unreviewed
CVE-2023-3614
was published
Jul 17, 2023
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and...
Low
Unreviewed
CVE-2022-4952
was published
Jul 17, 2023
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754,...
Low
Unreviewed
CVE-2023-32114
was published
Jun 13, 2023
RuoYi Uncontrolled Resource Consumption vulnerability
Low
CVE-2023-3163
was published
for
com.ruoyi:ruoyi
(Maven)
Jun 8, 2023
Microsoft Access Denial of Service Vulnerability
Low
Unreviewed
CVE-2023-29333
was published
May 9, 2023
Denial of Service Vulnerability in Rack Content-Disposition parsing
Low
CVE-2022-44571
was published
for
rack
(RubyGems)
Jan 18, 2023
ReDoS based DoS vulnerability in Action Dispatch
Low
CVE-2023-22792
was published
for
actionpack
(RubyGems)
Jan 18, 2023
Denial of service via multipart parsing in Rack
Low
CVE-2022-44572
was published
for
rack
(RubyGems)
Jan 18, 2023
EnumStringValues vulnerable to Uncontrolled Resource Consumption
Low
CVE-2020-36620
was published
for
EnumStringValues
(NuGet)
Dec 21, 2022
hutool-json vulnerable to memory exhaustion
Low
CVE-2022-45689
was published
for
cn.hutool:hutool-json
(Maven)
Dec 13, 2022
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing...
Low
Unreviewed
CVE-2022-33747
was published
Oct 11, 2022
Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability...
Low
Unreviewed
CVE-2021-25227
was published
May 24, 2022
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python...
Low
Unreviewed
CVE-2021-3737
was published
May 24, 2022
There is a resource management errors vulnerability in Huawei P30. Local attackers construct...
Low
Unreviewed
CVE-2020-9203
was published
May 24, 2022
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could...
Low
Unreviewed
CVE-2020-3504
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API