GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
53 advisories
Filter by severity
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-37988
was published
Jul 9, 2024
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-37989
was published
Jul 9, 2024
A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could...
Moderate
Unreviewed
CVE-2024-20416
was published
Jul 17, 2024
Django vulnerable to Denial of Service
High
CVE-2024-38875
was published
for
Django
(pip)
Jul 10, 2024
Django vulnerable to Denial of Service
High
CVE-2024-39614
was published
for
Django
(pip)
Jul 10, 2024
Django vulnerable to a denial-of-service attack
Moderate
CVE-2024-41990
was published
for
Django
(pip)
Aug 7, 2024
Django vulnerable to denial-of-service attack
Moderate
CVE-2024-41991
was published
for
Django
(pip)
Aug 7, 2024
Elliptic's ECDSA missing check for whether leading bit of r and s is zero
Low
CVE-2024-42460
was published
for
elliptic
(npm)
Aug 2, 2024
Out-of-bounds write vulnerability in the HAL-WIFI module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-47293
was published
Sep 27, 2024
rdiffweb's unlimited username field length can lead to DoS
High
CVE-2022-3290
was published
for
rdiffweb
(pip)
Sep 27, 2022
rPGP Panics on Malformed Untrusted Input
High
CVE-2024-53856
was published
for
pgp
(Rust)
Dec 5, 2024
Tor path lengths too short when "full Vanguards" configured
Moderate
CVE-2024-35313
was published
for
arti
(Rust)
May 18, 2024
An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2025-30659
was published
Apr 9, 2025
In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR...
Low
Unreviewed
CVE-2025-32366
was published
Apr 7, 2025
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The...
Moderate
Unreviewed
CVE-2025-29931
was published
Apr 17, 2025
The communication framework module has a vulnerability of not truncating data properly.Successful...
High
Unreviewed
CVE-2022-41586
was published
Oct 14, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27862
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
rdiffweb's unlimited length email field can lead to DoS
High
CVE-2022-3272
was published
for
rdiffweb
(pip)
Sep 27, 2022
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a...
Moderate
Unreviewed
CVE-2025-23247
was published
May 27, 2025
Improper handling of length parameter inconsistency vulnerability in Mitsubishi Electric FA...
Critical
Unreviewed
CVE-2021-20588
was published
May 24, 2022
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate
CVE-2025-53604
was published
for
web-push
(Rust)
Jul 5, 2025
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol...
High
Unreviewed
CVE-2025-52949
was published
Jul 11, 2025
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
Moderate
GHSA-624c-2h52-gf7f
was published
for
rosenpass
(Rust)
Jul 28, 2025
•
withdrawn
Remotely exploitable denial of service in Rosenpass
Moderate
CVE-2023-53157
was published
for
rosenpass
(Rust)
Dec 21, 2023
ProTip!
Advisories are also available from the
GraphQL API