GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,036 advisories
Filter by severity
In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource...
Moderate
Unreviewed
CVE-2021-0993
was published
Dec 16, 2021
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14...
Moderate
Unreviewed
CVE-2021-39932
was published
Dec 14, 2021
A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all...
Moderate
Unreviewed
CVE-2021-39938
was published
Dec 14, 2021
An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions...
Moderate
Unreviewed
CVE-2021-39939
was published
Dec 14, 2021
Prototype pollution in paypal-adaptive
Moderate
CVE-2020-7643
was published
for
paypal-adaptive
(npm)
Dec 10, 2021
Improper Input Validation in is-email
High
CVE-2021-36716
was published
for
is-email
(npm)
Dec 10, 2021
Uncontrolled Resource Consumption in strapi
Moderate
CVE-2020-8123
was published
for
strapi-admin
(npm)
Dec 10, 2021
Remote code injection in Log4j
Critical
CVE-2021-44228
was published
for
com.guicedee.services:log4j-core
(Maven)
Dec 10, 2021
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service,...
High
Unreviewed
CVE-2021-38951
was published
Dec 10, 2021
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and...
High
Unreviewed
CVE-2021-41014
was published
Dec 9, 2021
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular...
High
Unreviewed
CVE-2021-44686
was published
Dec 8, 2021
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22...
High
Unreviewed
CVE-2021-22956
was published
Dec 8, 2021
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22...
High
Unreviewed
CVE-2021-22955
was published
Dec 8, 2021
A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious...
Moderate
Unreviewed
CVE-2021-44527
was published
Dec 8, 2021
There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful...
High
Unreviewed
CVE-2021-37061
was published
Dec 8, 2021
There is a Resource Management Errors vulnerability in Huawei Smartphone.Successful exploitation...
High
Unreviewed
CVE-2021-37068
was published
Dec 8, 2021
Uncontrolled Resource Consumption vulnerability in MELSEC iQ-R Series R00/01/02CPU Firmware...
High
Unreviewed
CVE-2021-20609
was published
Dec 2, 2021
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s...
Moderate
Unreviewed
CVE-2021-42120
was published
Dec 1, 2021
The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing...
Moderate
Unreviewed
CVE-2021-24894
was published
Nov 24, 2021
Dell Networking OS10, versions 10.4.3.x, 10.5.0.x, 10.5.1.x & 10.5.2.x, contain an uncontrolled...
Moderate
Unreviewed
CVE-2021-36310
was published
Nov 21, 2021
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
Moderate
CVE-2021-3912
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
Infinite certificate chain depth results in OctoRPKI running forever
Moderate
CVE-2021-3908
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
Infinite open connection causes OctoRPKI to hang forever
Moderate
CVE-2021-3909
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
ReDoS vulnerability in parser_apache2
Moderate
CVE-2021-41186
was published
for
fluentd
(RubyGems)
Nov 1, 2021
ProTip!
Advisories are also available from the
GraphQL API