GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
302 advisories
Filter by severity
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the...
High
Unreviewed
CVE-2022-46285
was published
Feb 7, 2023
Denial of Service in Apache Commons Compress
High
CVE-2019-12402
was published
for
io.github.1tchy.java9modular.org.apache.commons:commons-compress
(Maven)
Oct 11, 2019
Istio vulnerable to denial of service
High
CVE-2019-18817
was published
for
istio.io/istio
(Go)
May 24, 2022
Loop with Unreachable Exit Condition in Netty
High
CVE-2016-4970
was published
for
io.netty:netty-handler
(Maven)
May 13, 2022
asyncua vulnerable to denial of service via infinite loop
High
CVE-2023-26151
was published
for
asyncua
(pip)
Oct 3, 2023
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply...
High
Unreviewed
CVE-2022-23098
was published
Feb 10, 2022
Invalid handling of `X509_verify_cert()` internal errors in libssl
High
CVE-2021-4044
was published
for
openssl-src
(Rust)
Dec 15, 2021
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300...
High
Unreviewed
CVE-2023-1718
was published
Nov 1, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35139
was published
for
ryu
(pip)
Aug 11, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35141
was published
for
ryu
(pip)
Aug 11, 2023
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc...
High
Unreviewed
CVE-2023-40458
was published
Nov 30, 2023
Candid infinite decoding loop through specially crafted payload
High
CVE-2023-6245
was published
for
candid
(Rust)
Dec 8, 2023
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of...
High
Unreviewed
CVE-2023-50981
was published
Dec 27, 2023
hutool-core discovered to contain an infinite loop in the StrSplitter.splitByRegex function
High
CVE-2023-51075
was published
for
cn.hutool:hutool-core
(Maven)
Dec 27, 2023
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that...
High
Unreviewed
CVE-2023-43511
was published
Jan 2, 2024
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco...
High
Unreviewed
CVE-2023-20083
was published
Nov 1, 2023
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV...
High
Unreviewed
CVE-2023-20197
was published
Aug 17, 2023
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application...
High
Unreviewed
CVE-2023-20020
was published
Jan 20, 2023
In Apache Tomcat there is an improper handing of overflow in the UTF-8 decoder
High
CVE-2018-1336
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 17, 2018
Infinite Loop in Apache Tomcat
High
CVE-2020-13935
was published
for
org.apache.tomcat:tomcat
(Maven)
Feb 8, 2022
** DISPUTED ** The deserialize function in serialize-to-js through 1.1.1 allows attackers to...
High
Unreviewed
CVE-2017-15871
was published
May 13, 2022
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy.
High
Unreviewed
CVE-2019-25040
was published
May 24, 2022
** DISPUTED ** Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special...
High
Unreviewed
CVE-2020-15598
was published
May 24, 2022
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service...
High
Unreviewed
CVE-2019-18217
was published
May 24, 2022
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in...
High
Unreviewed
CVE-2019-5097
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API