GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,640
Maven
5,000+
npm
4,265
NuGet
760
pip
4,061
Pub
12
RubyGems
956
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,315 advisories
Filter by severity
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed...
High
Unreviewed
CVE-2025-55670
was published
Oct 15, 2025
When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed traffic can cause...
High
Unreviewed
CVE-2025-53521
was published
Oct 15, 2025
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF...
Moderate
Unreviewed
CVE-2025-58474
was published
Oct 15, 2025
An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version...
High
Unreviewed
CVE-2024-10650
was published
Mar 20, 2025
A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of...
High
Unreviewed
CVE-2024-10714
was published
Mar 20, 2025
A denial-of-service security issue exists in the affected product and version. The security issue...
High
Unreviewed
CVE-2025-9177
was published
Oct 14, 2025
Apache Struts vulnerable to memory exhaustion
High
CVE-2023-34396
was published
for
org.apache.struts:struts-core
(Maven)
Jun 14, 2023
IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of...
Moderate
Unreviewed
CVE-2025-36171
was published
Oct 9, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3...
High
Unreviewed
CVE-2025-10004
was published
Oct 9, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8,...
Moderate
Unreviewed
CVE-2025-2934
was published
Oct 9, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44012
was published
Oct 3, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2025-20370
was published
Oct 1, 2025
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
High
CVE-2025-11362
was published
for
pdfmake
(npm)
Oct 7, 2025
A denial-of-service attack is possible through the execution functionality of KNIME Business Hub...
High
Unreviewed
CVE-2024-6598
was published
Jul 9, 2024
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44007
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44006
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-33039
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-33040
was published
Oct 3, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
If a user tries to login but the provided credentials are incorrect a log is created. The data...
Moderate
Unreviewed
CVE-2025-58582
was published
Oct 6, 2025
A user with the appropriate authorization can create any number of user accounts via an API ...
Low
Unreviewed
CVE-2025-58578
was published
Oct 6, 2025
Denial of service condition in M-Files Server in versions before
25.1.14445.5 allows an...
Moderate
Unreviewed
CVE-2025-0635
was published
Jan 23, 2025
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
A vulnerability has been found in Dahua products.Attackers
can send carefully crafted data...
High
Unreviewed
CVE-2024-39944
was published
Jul 31, 2024
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by...
Moderate
Unreviewed
CVE-2025-36099
was published
Sep 29, 2025
ProTip!
Advisories are also available from the
GraphQL API