GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
765
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
637 advisories
Filter by severity
Salt's worker process vulnerable to denial of service through file read operation
Moderate
CVE-2025-22242
was published
for
salt
(pip)
Jun 13, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17...
Moderate
Unreviewed
CVE-2025-5996
was published
Jun 12, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17...
Moderate
Unreviewed
CVE-2025-1516
was published
Jun 12, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17...
Moderate
Unreviewed
CVE-2025-1478
was published
Jun 12, 2025
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled...
Moderate
Unreviewed
CVE-2025-4605
was published
Jun 11, 2025
Resource allocation control failure vulnerability in the ArkUI framework
Impact: Successful...
Moderate
Unreviewed
CVE-2024-58114
was published
Jun 6, 2025
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash...
Moderate
Unreviewed
CVE-2025-5683
was published
Jun 5, 2025
ReDoS Vulnerability in Rack::Multipart handle_mime_head
Moderate
CVE-2025-49007
was published
for
rack
(RubyGems)
Jun 5, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1...
Moderate
Unreviewed
CVE-2025-3050
was published
May 29, 2025
An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11,...
Moderate
Unreviewed
CVE-2025-48738
was published
May 23, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17...
Moderate
Unreviewed
CVE-2024-7803
was published
May 23, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17...
Moderate
Unreviewed
CVE-2025-3111
was published
May 22, 2025
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before...
Moderate
Unreviewed
CVE-2025-2853
was published
May 22, 2025
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows...
Moderate
Unreviewed
CVE-2025-29954
was published
May 13, 2025
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker...
Moderate
Unreviewed
CVE-2025-29957
was published
May 13, 2025
ring has some AES functions that may panic when overflow checking is enabled in
Moderate
CVE-2025-4432
was published
for
ring
(Rust)
May 9, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to...
Moderate
Unreviewed
CVE-2024-8973
was published
May 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
sound/virtio: Fix...
Moderate
Unreviewed
CVE-2025-37805
was published
May 8, 2025
Django has a denial-of-service possibility in strip_tags()
Moderate
CVE-2025-32873
was published
for
Django
(pip)
May 8, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1...
Moderate
Unreviewed
CVE-2025-0915
was published
May 5, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1...
Moderate
Unreviewed
CVE-2025-1000
was published
May 5, 2025
A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged)...
Moderate
Unreviewed
CVE-2025-24341
was published
Apr 30, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a...
Moderate
Unreviewed
CVE-2025-46687
was published
Apr 27, 2025
GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-733v-p3h5-qpq7
was published
for
@escape.tech/graphql-armor-cost-limit
(npm)
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API