GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
873 advisories
Filter by severity
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
rttys SQL Injection vulnerability
High
CVE-2022-38867
was published
for
github.com/zhaojh329/rttys
(Go)
Feb 16, 2023
Ollama Denial of Service (DoS) via Null Pointer Dereference
High
CVE-2025-0312
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow
High
CVE-2025-29072
was published
for
github.com/NethermindEth/juno
(Go)
Mar 27, 2025
Ollama DNS rebinding vulnerability
High
CVE-2024-28224
was published
for
github.com/ollama/ollama
(Go)
Apr 8, 2024
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
High
CVE-2025-24514
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
Ollama Allows Out-of-Bounds Read
High
CVE-2024-12055
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Divide By Zero vulnerability
High
CVE-2025-0317
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints
High
CVE-2025-25068
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Ollama Vulnerable to Denial of Service (DoS) via Crafted GZIP
High
CVE-2024-12886
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
CoreDNS vulnerable to TuDoor Attacks
High
CVE-2023-28452
was published
for
github.com/coredns/coredns
(Go)
Sep 18, 2024
Openshift Hive Exposes VCenter Credentials via ClusterProvision
High
CVE-2025-2241
was published
for
github.com/openshift/hive
(Go)
Mar 17, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
Non-linear parsing of case-insensitive content in golang.org/x/net/html
High
CVE-2024-45338
was published
for
golang.org/x/net/html
(Go)
Dec 18, 2024
Vela Server Has Insufficient Webhook Payload Data Verification
High
CVE-2025-27616
was published
for
github.com/go-vela/server
(Go)
Mar 10, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
kubevirt-csi: PersistentVolume allows access to HCP's root node
High
CVE-2024-1725
was published
for
github.com/kubevirt/csi-driver
(Go)
Mar 7, 2024
Cosmos SDK: x/group can halt when erroring in EndBlocker
High
GHSA-47ww-ff84-4jrg
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Mar 12, 2025
Karmada PULL Mode Cluster Privilege Escalation
High
CVE-2024-56513
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
Horcrux Double Sign Possibility
High
GHSA-6wxf-7784-62fp
was published
for
github.com/strangelove-ventures/horcrux/v3
(Go)
Mar 7, 2025
ProTip!
Advisories are also available from the
GraphQL API