GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,316 advisories
Filter by severity
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
Moderate
Unreviewed
CVE-2022-42313
was published
Nov 1, 2022
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
Moderate
Unreviewed
CVE-2022-42314
was published
Nov 1, 2022
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
High
Unreviewed
CVE-2022-42311
was published
Nov 1, 2022
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
Moderate
Unreviewed
CVE-2022-42317
was published
Nov 1, 2022
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
Moderate
Unreviewed
CVE-2022-42316
was published
Nov 1, 2022
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to...
Moderate
Unreviewed
CVE-2022-42318
was published
Nov 1, 2022
In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process...
High
Unreviewed
CVE-2021-46828
was published
Jul 21, 2022
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged)...
Moderate
Unreviewed
CVE-2025-24341
was published
Apr 30, 2025
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
Moderate
CVE-2025-2559
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 25, 2025
GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-733v-p3h5-qpq7
was published
for
@escape.tech/graphql-armor-cost-limit
(npm)
Apr 25, 2025
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a...
Moderate
Unreviewed
CVE-2025-46687
was published
Apr 27, 2025
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Moderate
CVE-2025-35965
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
Denial of service due to allocation of resources without limits. The following products are...
Moderate
Unreviewed
CVE-2025-30409
was published
Apr 24, 2025
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE...
Moderate
Unreviewed
CVE-2025-0639
was published
Apr 24, 2025
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of...
Moderate
Unreviewed
CVE-2023-45873
was published
Feb 29, 2024
Cuba has a DoS in the File Storage
Moderate
CVE-2025-32959
was published
for
com.haulmont.cuba:cuba-core
(Maven)
Apr 22, 2025
tar-split memory exhaustion
Moderate
CVE-2017-14992
was published
for
github.com/vbatts/tar-split
(Go)
May 17, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20485
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20480
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20484
was published
Dec 13, 2022
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist...
High
Unreviewed
CVE-2022-20479
was published
Dec 13, 2022
ProTip!
Advisories are also available from the
GraphQL API