GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,076
Erlang
29
GitHub Actions
19
Go
1,895
Maven
5,000+
npm
3,630
NuGet
638
pip
3,244
Pub
10
RubyGems
862
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,317 advisories
Filter by severity
A denial-of-service vulnerability could allow an authenticated user to trigger an internal...
Low
Unreviewed
CVE-2022-4003
was published
Jul 31, 2024
An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to...
Moderate
Unreviewed
CVE-2024-37281
was published
Jul 31, 2024
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma...
Moderate
Unreviewed
CVE-2024-27862
was published
Jul 30, 2024
fast-xml-parser vulnerable to ReDOS at currency parsing
High
CVE-2024-41818
was published
for
fast-xml-parser
(npm)
Jul 29, 2024
An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing...
Moderate
Unreviewed
CVE-2024-3297
was published
Jul 24, 2024
Argo CD Unauthenticated Denial of Service (DoS) Vulnerability via /api/webhook Endpoint
High
CVE-2024-40634
was published
for
github.com/argoproj/argo-cd
(Go)
Jul 22, 2024
DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources
Moderate
GHSA-mmwx-rj87-vfgr
was published
for
dnsjava:dnsjava
(Maven)
Jul 22, 2024
Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. ...
Moderate
Unreviewed
CVE-2024-21126
was published
Jul 17, 2024
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-5795
was published
Jul 17, 2024
REXML denial of service vulnerability
Moderate
CVE-2024-39908
was published
for
rexml
(RubyGems)
Jul 16, 2024
Fiona affected by CVE-2020-14152 related to madler-zlib
High
GHSA-g4m4-9q4c-mfw6
was published
for
fiona
(pip)
Jul 16, 2024
A flaw was found in libtiff. This flaw allows an attacker to create a crafted tiff file, forcing...
Moderate
Unreviewed
CVE-2024-6716
was published
Jul 15, 2024
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function...
Moderate
Unreviewed
CVE-2023-39329
was published
Jul 13, 2024
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a...
Moderate
Unreviewed
CVE-2023-39327
was published
Jul 13, 2024
An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks...
High
Unreviewed
CVE-2024-39548
was published
Jul 11, 2024
An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway)...
High
Unreviewed
CVE-2024-39551
was published
Jul 11, 2024
An Uncontrolled Resource Consumption vulnerability in the
Layer 2 Address Learning Daemon ...
High
Unreviewed
CVE-2024-39557
was published
Jul 11, 2024
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the...
High
Unreviewed
CVE-2024-6036
was published
Jul 11, 2024
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create...
High
Unreviewed
CVE-2024-6037
was published
Jul 11, 2024
Next.js Denial of Service (DoS) condition
High
CVE-2024-39693
was published
for
next
(npm)
Jul 10, 2024
speaker vulnerable to Denial of Service
High
CVE-2024-21526
was published
for
speaker
(npm)
Jul 10, 2024
images vulnerable to Denial of Service
High
CVE-2024-21523
was published
for
images
(npm)
Jul 10, 2024
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with...
High
Unreviewed
CVE-2024-29153
was published
Jul 9, 2024
A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled...
Low
Unreviewed
CVE-2024-6501
was published
Jul 9, 2024
Microsoft Security Advisory CVE-2024-30105 | .NET Denial of Service Vulnerability
High
CVE-2024-30105
was published
for
System.Text.Json
(NuGet)
Jul 9, 2024
ProTip!
Advisories are also available from the
GraphQL API