GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,366 advisories
Filter by severity
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21218
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2024-21230
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21207
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported...
Moderate
Unreviewed
CVE-2024-21204
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported...
Moderate
Unreviewed
CVE-2024-21203
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). ...
Moderate
Unreviewed
CVE-2024-21196
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21194
was published
Oct 15, 2024
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Moderate
CVE-2024-8184
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 14, 2024
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2024-45736
was published
Oct 14, 2024
Eclipse Jetty has a denial of service vulnerability on DosFilter
Moderate
CVE-2024-9823
was published
for
org.eclipse.jetty.ee10:jetty-ee10-servlets
(Maven)
Oct 14, 2024
Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before...
Moderate
Unreviewed
CVE-2023-25769
was published
Oct 10, 2024
Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters
Moderate
CVE-2024-45230
was published
for
Django
(pip)
Oct 8, 2024
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series...
Moderate
Unreviewed
CVE-2024-20502
was published
Oct 2, 2024
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series...
Moderate
Unreviewed
CVE-2024-20500
was published
Oct 2, 2024
A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected...
Moderate
Unreviewed
CVE-2024-9358
was published
Oct 1, 2024
The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain...
Moderate
Unreviewed
CVE-2024-8454
was published
Sep 30, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Moderate
CVE-2024-47003
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Sep 26, 2024
Denial of service in rocket chat message parser
Moderate
CVE-2024-46935
was published
for
@rocket.chat/message-parser
(npm)
Sep 25, 2024
Spring Framework DoS via conditional HTTP request
Moderate
CVE-2024-38809
was published
for
org.springframework:spring-web
(Maven)
Sep 24, 2024
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify...
Moderate
Unreviewed
CVE-2024-8892
was published
Sep 18, 2024
vLLM Denial of Service via the best_of parameter
Moderate
CVE-2024-8939
was published
for
vllm
(pip)
Sep 17, 2024
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in...
Moderate
Unreviewed
CVE-2024-44176
was published
Sep 17, 2024
A logic error was addressed with improved error handling. This issue is fixed in macOS Ventura 13...
Moderate
Unreviewed
CVE-2024-44183
was published
Sep 17, 2024
A memory initialization issue was addressed with improved memory handling. This issue is fixed in...
Moderate
Unreviewed
CVE-2024-44154
was published
Sep 17, 2024
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column)...
Moderate
Unreviewed
CVE-2024-41434
was published
Sep 3, 2024
ProTip!
Advisories are also available from the
GraphQL API