GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
586 advisories
Filter by severity
In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive...
High
Unreviewed
CVE-2022-42531
was published
Dec 21, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20486
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20487
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20478
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20479
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20480
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20485
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20484
was published
Dec 13, 2022
libp2p DoS vulnerability from lack of resource management
High
CVE-2022-23487
was published
for
libp2p
(npm)
Dec 7, 2022
libp2p DoS vulnerability from lack of resource management
High
CVE-2022-23486
was published
for
libp2p
(Rust)
Dec 7, 2022
Creation of new database tables through login form on PostgreSQL
High
CVE-2022-41932
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Nov 21, 2022
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular...
High
Unreviewed
CVE-2022-45471
was published
Nov 18, 2022
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a...
High
Unreviewed
CVE-2021-34568
was published
Nov 9, 2022
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer...
High
Unreviewed
CVE-2022-43945
was published
Nov 5, 2022
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
High
Unreviewed
CVE-2022-42311
was published
Nov 1, 2022
Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or...
High
Unreviewed
CVE-2022-34439
was published
Oct 21, 2022
A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS...
High
Unreviewed
CVE-2022-22211
was published
Oct 18, 2022
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted...
High
Unreviewed
CVE-2022-2879
was published
Oct 14, 2022
rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks
High
CVE-2022-3273
was published
for
rdiffweb
(pip)
Oct 6, 2022
rdiffweb's lack of token name length limit can result in DoS or memory corruption
High
CVE-2022-3371
was published
for
rdiffweb
(pip)
Oct 1, 2022
rdiffweb allows unlimited length of root directory name, which could result in DoS
High
CVE-2022-3295
was published
for
rdiffweb
(pip)
Sep 27, 2022
rdiffweb vulnerable to potential DoS via memory consumption
High
CVE-2022-3298
was published
for
rdiffweb
(pip)
Sep 27, 2022
Apache Kafka vulnerability can lead to brokers hitting OutOfMemoryException, causing Denial of Service
High
CVE-2022-34917
was published
for
org.apache.kafka:kafka
(Maven)
Sep 21, 2022
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung...
High
Unreviewed
CVE-2022-40762
was published
Sep 17, 2022
Helm Controller denial of service
High
CVE-2022-36049
was published
for
github.com/fluxcd/flux2
(Go)
Sep 16, 2022
ProTip!
Advisories are also available from the
GraphQL API