GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,051 advisories
Filter by severity
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the...
High
Unreviewed
CVE-2024-31309
was published
Apr 10, 2024
Magento Open Source allows Improper Input Validation
High
CVE-2024-20758
was published
for
magento/community-edition
(Composer)
Apr 10, 2024
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-26240
was published
Apr 9, 2024
Secure Boot Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-26189
was published
Apr 9, 2024
Input verification vulnerability in the log module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-27896
was published
Apr 8, 2024
Input verification vulnerability in the power module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2023-52552
was published
Apr 8, 2024
A denial of service vulnerability was reported in some Lenovo Printers that could allow an...
High
Unreviewed
CVE-2024-27912
was published
Apr 5, 2024
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API...
High
Unreviewed
CVE-2024-0335
was published
Apr 3, 2024
in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.
High
Unreviewed
CVE-2024-28226
was published
Apr 2, 2024
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in...
High
Unreviewed
CVE-2023-33099
was published
Apr 1, 2024
Transient DOS while processing DL NAS Transport message when message ID is not defined in the...
High
Unreviewed
CVE-2023-33100
was published
Apr 1, 2024
Transient DOS while decoding message of size that exceeds the available system memory.
High
Unreviewed
CVE-2024-21453
was published
Apr 1, 2024
Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.
High
Unreviewed
CVE-2024-21452
was published
Apr 1, 2024
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub in the...
High
Unreviewed
CVE-2024-29946
was published
Mar 27, 2024
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an...
High
Unreviewed
CVE-2024-20271
was published
Mar 27, 2024
An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to...
High
Unreviewed
CVE-2023-46047
was published
Mar 27, 2024
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling...
High
Unreviewed
CVE-2023-29134
was published
Mar 27, 2024
The ZScaler service is susceptible to a local privilege escalation vulnerability found in the...
High
Unreviewed
CVE-2024-23482
was published
Mar 26, 2024
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to...
High
Unreviewed
CVE-2024-2427
was published
Mar 25, 2024
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to...
High
Unreviewed
CVE-2024-2426
was published
Mar 25, 2024
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to...
High
Unreviewed
CVE-2024-2425
was published
Mar 25, 2024
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via...
High
Unreviewed
CVE-2024-2469
was published
Mar 21, 2024
Arbitrary file upload vulnerability in GeoServer's REST Coverage Store API
High
CVE-2023-51444
was published
for
org.geoserver:gs-platform
(Maven)
Mar 20, 2024
Improper HTML sanitization in ZITADEL
High
CVE-2024-28855
was published
for
github.com/zitadel/zitadel
(Go)
Mar 18, 2024
ProTip!
Advisories are also available from the
GraphQL API