GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
51 advisories
Filter by severity
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet...
High
Unreviewed
CVE-2021-4190
was published
Dec 31, 2021
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
In ImageMagick 7.0.7-16 Q16, a vulnerability was found in the function ReadOnePNGImage in coders...
High
Unreviewed
CVE-2017-17914
was published
May 13, 2022
In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an...
High
Unreviewed
CVE-2017-14174
was published
May 13, 2022
In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of...
High
Unreviewed
CVE-2017-14175
was published
May 13, 2022
In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of...
High
Unreviewed
CVE-2017-14172
was published
May 13, 2022
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex...
High
Unreviewed
CVE-2017-13776
was published
May 13, 2022
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex...
High
Unreviewed
CVE-2017-13777
was published
May 13, 2022
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
High
Unreviewed
CVE-2017-12587
was published
May 13, 2022
In ImageMagick 7.0.6-2, a CPU exhaustion vulnerability was found in the function ReadPDBImage in...
High
Unreviewed
CVE-2017-12674
was published
May 13, 2022
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was...
High
Unreviewed
CVE-2017-11409
was published
May 13, 2022
In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a...
High
Unreviewed
CVE-2024-4227
was published
Jan 15, 2025
In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server...
High
Unreviewed
CVE-2023-5632
was published
Oct 18, 2023
srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU...
High
Unreviewed
CVE-2020-35573
was published
May 24, 2022
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of...
High
Unreviewed
CVE-2019-3559
was published
May 24, 2022
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of...
High
Unreviewed
CVE-2024-0842
was published
Feb 9, 2024
Denial of service in HashiCorp Consul
High
CVE-2020-25201
was published
for
github.com/hashicorp/consul
(Go)
Jan 31, 2024
phpseclib vulnerable to denial of service
High
CVE-2023-49316
was published
for
phpseclib/phpseclib
(Composer)
Nov 27, 2023
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
High
CVE-2023-38200
was published
for
keylime
(pip)
Aug 1, 2023
Improper Input Validation and Excessive Iteration in Go Facebook Thrift
High
CVE-2019-3564
was published
for
github.com/facebook/fbthrift
(Go)
Feb 15, 2022
Apache Sling Resource Merger has Excessive Iteration vulnerability
High
CVE-2023-26513
was published
for
org.apache.sling:org.apache.sling.resourcemerger
(Maven)
Mar 20, 2023
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop...
High
Unreviewed
CVE-2018-9261
was published
May 13, 2022
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 ...
High
Unreviewed
CVE-2017-9255
was published
May 13, 2022
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 ...
High
Unreviewed
CVE-2017-9253
was published
May 13, 2022
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 ...
High
Unreviewed
CVE-2017-9256
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API