GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
463 advisories
Filter by severity
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows...
Moderate
Unreviewed
CVE-2023-42559
was published
Dec 5, 2023
Unauthenticated Denial of Service in the octokit/webhooks library
High
CVE-2023-50728
was published
for
@octokit/app
(npm)
Dec 16, 2023
There is a denial of service vulnerability in some ZTE mobile internet products. Due to...
Moderate
Unreviewed
CVE-2023-25644
was published
Dec 14, 2023
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because...
Critical
Unreviewed
CVE-2023-47100
was published
Dec 3, 2023
Microweber missing standardized error handling mechanism
Low
CVE-2023-6599
was published
for
microweber/microweber
(Composer)
Dec 8, 2023
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially...
High
Unreviewed
CVE-2023-22292
was published
Nov 14, 2023
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
High
Unreviewed
CVE-2023-44488
was published
Sep 30, 2023
Elasticsearch Improper Handling of Exceptional Conditions
Moderate
CVE-2023-46673
was published
for
org.elasticsearch:elasticsearch
(Maven)
Nov 22, 2023
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient...
Moderate
Unreviewed
CVE-2023-43087
was published
Nov 2, 2023
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior...
Moderate
Unreviewed
CVE-2021-23886
was published
May 24, 2022
Calico Typha denial of service vulnerability
High
CVE-2023-41378
was published
for
github.com/projectcalico/calico
(Go)
Nov 6, 2023
Specific Cilium configurations vulnerable to DoS via Kubernetes annotations
Low
CVE-2023-41332
was published
for
github.com/cilium/cilium
(Go)
Sep 27, 2023
Apollo Router Unnamed "Subscription" operation results in Denial-of-Service
Moderate
CVE-2023-41317
was published
for
apollo-router
(Rust)
Sep 7, 2023
Improper random reading in CIRCL
Moderate
CVE-2023-1732
was published
for
github.com/cloudflare/circl
(Go)
May 11, 2023
Directus crashes on invalid WebSocket message
High
CVE-2023-45820
was published
for
directus
(npm)
Oct 19, 2023
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash,...
Unknown
Unreviewed
CVE-2023-3774
was published
Jul 28, 2023
XWiki Platform vulnerable to page render failure due to broken translations
Moderate
CVE-2023-29520
was published
for
org.xwiki.platform:xwiki-platform-localization-source-wiki
(Maven)
Apr 20, 2023
Perdition before 2.2 may have weak security when handling outbound connections, caused by an...
Moderate
Unreviewed
CVE-2013-4584
was published
May 5, 2022
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client...
Moderate
Unreviewed
CVE-2019-10222
was published
May 24, 2022
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper...
Moderate
Unreviewed
CVE-2022-21813
was published
Feb 8, 2022
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where...
Moderate
Unreviewed
CVE-2022-21814
was published
Feb 8, 2022
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources
High
CVE-2021-28165
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Apr 6, 2021
DoS attack can be performed when an email contains specially designed URL in the body. It can...
Moderate
Unreviewed
CVE-2021-21439
was published
May 24, 2022
Improper Input Validation and Excessive Iteration in Go Facebook Thrift
High
CVE-2019-3564
was published
for
github.com/facebook/fbthrift
(Go)
Feb 15, 2022
In apusys, there is a possible memory corruption due to a missing bounds check. This could lead...
Moderate
Unreviewed
CVE-2021-0679
was published
Dec 18, 2021
ProTip!
Advisories are also available from the
GraphQL API