GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,316 advisories
Filter by severity
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause...
Moderate
Unreviewed
CVE-2024-34055
was published
Jun 5, 2024
is_closing_session() allows users to fill up apport.log
Moderate
Unreviewed
CVE-2022-28654
was published
Jun 5, 2024
is_closing_session() allows users to create arbitrary tcp dbus connections
High
Unreviewed
CVE-2022-28655
was published
Jun 5, 2024
is_closing_session() allows users to consume RAM in the Apport process
Moderate
Unreviewed
CVE-2022-28656
was published
Jun 5, 2024
Flooding Server with Thumbnail files
High
CVE-2024-32871
was published
for
pimcore/pimcore
(Composer)
Jun 4, 2024
TYPO3 Denial of Service in Frontend Record Registration
High
GHSA-hjx5-v9xg-7h25
was published
for
typo3/cms-core
(Composer)
May 30, 2024
TYPO3 Denial of Service in Online Media Asset Handling
Moderate
GHSA-29m4-mx89-3mjg
was published
for
typo3/cms-core
(Composer)
May 30, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations
Moderate
CVE-2024-35238
was published
for
github.com/stacklok/minder
(Go)
May 28, 2024
rack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter
High
CVE-2024-35231
was published
for
rack-contrib
(RubyGems)
May 28, 2024
An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11...
Moderate
Unreviewed
CVE-2024-2874
was published
May 23, 2024
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Moderate
Unreviewed
CVE-2024-31617
was published
May 22, 2024
In the Linux kernel, the following vulnerability has been resolved:
dma-debug: prevent an error...
Moderate
Unreviewed
CVE-2021-47374
was published
May 21, 2024
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix race condition...
Moderate
Unreviewed
CVE-2024-35969
was published
May 20, 2024
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that...
Moderate
Unreviewed
CVE-2023-47717
was published
May 16, 2024
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All...
Moderate
Unreviewed
CVE-2024-33495
was published
May 14, 2024
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without...
Moderate
Unreviewed
CVE-2024-25969
was published
May 14, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to...
Moderate
Unreviewed
CVE-2024-4539
was published
May 14, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to...
Moderate
Unreviewed
CVE-2024-2454
was published
May 14, 2024
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is...
Moderate
Unreviewed
CVE-2024-28760
was published
May 14, 2024
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS...
High
Unreviewed
CVE-2024-27804
was published
May 14, 2024
Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
Critical
CVE-2024-32874
was published
for
frigate
(pip)
May 9, 2024
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due...
Moderate
Unreviewed
CVE-2024-0026
was published
May 7, 2024
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to...
Moderate
Unreviewed
CVE-2024-0027
was published
May 7, 2024
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can...
High
Unreviewed
CVE-2024-4140
was published
May 2, 2024
Wildfly vulnerable to denial of service
Moderate
CVE-2024-4029
was published
for
org.wildfly:wildfly-domain-http
(Maven)
May 2, 2024
ProTip!
Advisories are also available from the
GraphQL API