GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
369 advisories
Filter by severity
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly...
Moderate
Unreviewed
CVE-2023-45290
was published
Mar 6, 2024
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API alwaysmulti.cgi...
Moderate
Unreviewed
CVE-2024-6509
was published
Sep 10, 2024
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Moderate
CVE-2024-8184
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 14, 2024
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of...
Moderate
Unreviewed
CVE-2024-21994
was published
Nov 8, 2024
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation...
Moderate
Unreviewed
CVE-2024-31152
was published
Oct 30, 2024
Memory exhaustion in Tensorflow
Moderate
CVE-2022-21732
was published
for
tensorflow
(pip)
Feb 10, 2022
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due...
Moderate
Unreviewed
CVE-2024-43083
was published
Nov 13, 2024
zlib-rs stack overflow during decompression with malicious input
Moderate
GHSA-j3px-q95c-9683
was published
for
libz-rs-sys
(Rust)
Nov 14, 2024
A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.254), Parasolid V36...
Moderate
Unreviewed
CVE-2024-26276
was published
Apr 9, 2024
Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2024-52918
was published
Nov 18, 2024
In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific...
Moderate
Unreviewed
CVE-2024-52913
was published
Nov 18, 2024
Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis...
Moderate
Unreviewed
CVE-2024-52917
was published
Nov 18, 2024
Missing ratelimit on passwrod resets in zenml
Moderate
CVE-2024-4311
was published
for
zenml
(pip)
Nov 14, 2024
Wagtail vulnerable to denial-of-service via memory exhaustion when uploading large files
Moderate
CVE-2023-28837
was published
for
wagtail
(pip)
Apr 3, 2023
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Moderate
Unreviewed
CVE-2024-31617
was published
May 22, 2024
Searching Opencast may cause a denial of service
Moderate
CVE-2024-52797
was published
for
org.opencastproject:opencast-elasticsearch-impl
(Maven)
Nov 20, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Moderate
Unreviewed
CVE-2024-20968
was published
Feb 17, 2024
Password Pusher rate limiter can be bypassed by forging proxy headers
Moderate
CVE-2024-52796
was published
for
pwpush
(RubyGems)
Nov 20, 2024
ProTip!
Advisories are also available from the
GraphQL API