GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
368 advisories
Filter by severity
Node DOS by way of memory exhaustion through ExecSync request in CRI-O
High
CVE-2022-1708
was published
for
github.com/cri-o/cri-o
(Go)
Jun 6, 2022
MediaWiki allows a denial of service
Moderate
CVE-2021-41800
was published
for
mediawiki/core
(Composer)
May 24, 2022
Liferay Portal and Liferay DXP vulnerable to email spam via lack of flagging rate
Moderate
CVE-2021-33320
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
NFStream Local Denial of Service (DoS)
Moderate
CVE-2020-25340
was published
for
nfstream
(pip)
May 24, 2022
Moodle Client side denial of service via personal message
Moderate
CVE-2021-20185
was published
for
moodle/moodle
(Composer)
May 24, 2022
Excessive memory allocation in graph URLs leads to denial of service in Jenkins
Moderate
CVE-2021-21607
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Golang Facebook Thrift servers vulnerable to denial of service
High
CVE-2019-11939
was published
for
github.com/facebook/fbthrift
(Go)
May 24, 2022
OpenStack os-vif Ageing time of 0 disables linuxbridge MAC learning
Critical
CVE-2019-15753
was published
for
os-vif
(pip)
May 24, 2022
golang.org/x/net/http vulnerable to a reset flood
High
CVE-2019-9514
was published
for
golang.org/x/net
(Go)
May 24, 2022
OpenStack Compute (Nova) does not verify the virtual size of a QCOW2 image
Moderate
CVE-2013-2096
was published
for
nova
(pip)
May 17, 2022
OpenStack Nova VMWare driver leaks rescued images
High
CVE-2014-2573
was published
for
nova
(pip)
May 17, 2022
Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream
High
CVE-2014-2829
was published
for
MongooseIM
(Erlang)
May 17, 2022
Plone is vulnerable to denial of service
High
CVE-2012-5499
was published
for
Plone
(pip)
May 17, 2022
Django database denial-of-service with ModelMultipleChoiceField
High
CVE-2015-0222
was published
for
Django
(pip)
May 17, 2022
OpenStack Glance Denial of service by creating a large number of images
High
CVE-2014-9684
was published
for
glance
(pip)
May 17, 2022
OpenStack Glance Denial of service by creating a large number of images
High
CVE-2015-1881
was published
for
glance
(pip)
May 17, 2022
priority vulnerable to denial of service
Moderate
CVE-2016-6580
was published
for
priority
(pip)
May 17, 2022
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
High
CVE-2013-1838
was published
for
nova
(pip)
May 17, 2022
Django denial of service via empty session record creation
Moderate
CVE-2015-5963
was published
for
Django
(pip)
May 17, 2022
tar-split memory exhaustion
Moderate
CVE-2017-14992
was published
for
github.com/vbatts/tar-split
(Go)
May 17, 2022
Apache Tika vulnerable to uncontrolled memory consumption
Moderate
CVE-2022-25169
was published
for
org.apache.tika:tika
(Maven)
May 17, 2022
Django Denial-of-service possibility with strip_tags
High
CVE-2015-2316
was published
for
Django
(pip)
May 14, 2022
ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payload
High
CVE-2017-13763
was published
for
org.onosproject:onos-base
(Maven)
May 13, 2022
Kubernetes DoS Vulnerability
Moderate
CVE-2019-1002100
was published
for
k8s.io/kubernetes
(Go)
May 13, 2022
Docker Registry has Allocation of Resources Without Limits or Throttling
High
CVE-2017-11468
was published
for
github.com/docker/distribution
(Go)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API