GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,112
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
295 advisories
Filter by severity
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users...
High
Unreviewed
CVE-2022-46770
was published
Dec 7, 2022
CodeIgniter4 DoS Vulnerability
High
CVE-2024-29904
was published
for
codeigniter4/framework
(Composer)
Mar 29, 2024
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
High
Unreviewed
CVE-2024-22654
was published
May 29, 2025
GeoServer Infinite Loop Vulnerability in Jiffle process
High
CVE-2025-30145
was published
for
org.geoserver.extension:gs-wps-core
(Maven)
Jun 10, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17...
High
Unreviewed
CVE-2025-0673
was published
Jun 12, 2025
An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume...
High
Unreviewed
CVE-2023-51890
was published
Jan 24, 2024
ZenML unauthenticated DoS via Multipart Boundry
High
CVE-2024-9340
was published
for
zenml
(pip)
Mar 20, 2025
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the...
High
Unreviewed
CVE-2020-28095
was published
May 24, 2022
ImageMagick has XMP profile write that triggers hang due to unbounded loop
High
CVE-2025-53015
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 23, 2025
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA)...
High
Unreviewed
CVE-2024-20353
was published
Apr 24, 2024
Due to a mistake in libcurl's WebSocket code, a malicious server can send a
particularly crafted...
High
Unreviewed
CVE-2025-5399
was published
Jun 7, 2025
quiche connection ID retirement can trigger an infinite loop
High
CVE-2025-7054
was published
for
quiche
(Rust)
Aug 7, 2025
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry...
High
Unreviewed
CVE-2025-8194
was published
Jul 28, 2025
A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA...
High
Unreviewed
CVE-2025-20253
was published
Aug 14, 2025
A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco...
High
Unreviewed
CVE-2025-20217
was published
Aug 14, 2025
A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS...
High
Unreviewed
CVE-2025-20136
was published
Aug 14, 2025
A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and...
High
Unreviewed
CVE-2025-20243
was published
Aug 14, 2025
An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12...
High
Unreviewed
CVE-2025-51986
was published
Aug 14, 2025
This vulnerability allows any attacker to cause the PeerTube server to stop responding to...
High
Unreviewed
CVE-2025-32947
was published
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API