GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming...
Low
Unreviewed
CVE-2025-30187
was published
Sep 18, 2025
Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp
Low
GHSA-g97w-mw7g-v3jv
was published
for
sequoia-openpgp
(Rust)
Jul 27, 2025
•
withdrawn
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high...
Low
Unreviewed
CVE-2025-42954
was published
Jul 8, 2025
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR...
Low
Unreviewed
CVE-2024-33623
was published
Oct 30, 2024
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack
Low
CVE-2024-45395
was published
for
github.com/sigstore/sigstore-go
(Go)
Sep 4, 2024
Low severity (DoS) vulnerability in sequoia-openpgp
Low
CVE-2024-58261
was published
for
sequoia-openpgp
(Rust)
Jun 26, 2024
Cosign vulnerable to possible endless data attack from attacker-controlled registry
Low
CVE-2023-46737
was published
for
github.com/sigstore/cosign
(Go)
Nov 8, 2023
A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up...
Low
Unreviewed
CVE-2015-10103
was published
Apr 17, 2023
linux-loader reading beyond EOF could lead to infinite loop
Low
CVE-2022-23523
was published
for
linux-loader
(Rust)
Dec 12, 2022
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the...
Low
Unreviewed
CVE-2020-14394
was published
Aug 18, 2022
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python...
Low
Unreviewed
CVE-2021-3737
was published
May 24, 2022
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8...
Low
Unreviewed
CVE-2019-12068
was published
May 24, 2022
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process...
Low
Unreviewed
CVE-2015-6815
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API