GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,316 advisories
Filter by severity
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2,...
Moderate
Unreviewed
CVE-2024-54501
was published
Dec 12, 2024
CGI has Denial of Service (DoS) potential in Cookie.parse
Moderate
CVE-2025-27219
was published
for
cgi
(RubyGems)
Mar 3, 2025
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong...
Moderate
Unreviewed
CVE-2025-26466
was published
Mar 1, 2025
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
High
CVE-2025-9784
was published
for
io.undertow:undertow-core
(Maven)
Sep 2, 2025
Apache Commons FileUpload denial of service vulnerability
High
CVE-2023-24998
was published
for
commons-fileupload:commons-fileupload
(Maven)
Feb 20, 2023
Ion Java StackOverflow vulnerability
High
CVE-2024-21634
was published
for
com.amazon.ion:ion-java
(Maven)
Jan 3, 2024
Tornado has an HTTP cookie parsing DoS vulnerability
High
CVE-2024-52804
was published
for
tornado
(pip)
Nov 22, 2024
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-28762
was published
Jun 12, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-31881
was published
Jun 12, 2024
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU...
Moderate
Unreviewed
CVE-2024-23184
was published
Sep 10, 2024
Very large headers can cause resource exhaustion when parsing message. The message-parser...
High
Unreviewed
CVE-2024-23185
was published
Sep 10, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-31880
was published
Oct 23, 2024
Django vulnerable to Denial of Service
High
CVE-2024-38875
was published
for
Django
(pip)
Jul 10, 2024
Django vulnerable to Denial of Service
High
CVE-2024-39614
was published
for
Django
(pip)
Jul 10, 2024
Certain DNSSEC aspects of the DNS protocol (in RFC 4035 and related RFCs) allow remote attackers...
High
Unreviewed
CVE-2023-50387
was published
Feb 14, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Moderate
Unreviewed
CVE-2024-20968
was published
Feb 17, 2024
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41840
was published
Feb 10, 2022
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1...
Moderate
Unreviewed
CVE-2023-51339
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Car Park...
Moderate
Unreviewed
CVE-2023-51310
was published
Feb 20, 2025
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to...
High
Unreviewed
CVE-2024-27316
was published
Apr 4, 2024
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Car Park Booking System v3...
Moderate
Unreviewed
CVE-2023-51309
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0...
Moderate
Unreviewed
CVE-2023-51334
was published
Feb 20, 2025
Django denial-of-service attack in the intcomma template filter
High
CVE-2024-24680
was published
for
Django
(pip)
Feb 7, 2024
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6,...
Moderate
Unreviewed
CVE-2025-43211
was published
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API