GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
637 advisories
Filter by severity
A low privileged remote attacker can use the ssh feature to execute commands directly after login...
Moderate
Unreviewed
CVE-2025-41693
was published
Dec 9, 2025
A low privileged remote attacker can run the webshell with an empty command containing whitespace...
Moderate
Unreviewed
CVE-2025-41694
was published
Dec 9, 2025
IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service...
Moderate
Unreviewed
CVE-2025-36140
was published
Dec 9, 2025
In multiple locations, there is a possible permanent denial of service due to resource exhaustion...
Moderate
Unreviewed
CVE-2025-48569
was published
Dec 8, 2025
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due...
Moderate
Unreviewed
CVE-2025-48603
was published
Dec 8, 2025
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-63402
was published
Dec 3, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18...
Moderate
Unreviewed
CVE-2025-7449
was published
Nov 26, 2025
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Moderate
CVE-2025-62426
was published
for
vllm
(pip)
Nov 20, 2025
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Moderate
CVE-2025-58181
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user...
Moderate
Unreviewed
CVE-2025-54320
was published
Nov 18, 2025
If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through...
Moderate
Unreviewed
CVE-2025-59089
was published
Nov 12, 2025
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of...
Moderate
Unreviewed
CVE-2025-12748
was published
Nov 11, 2025
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-36008
was published
Nov 7, 2025
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-36136
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53413
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53410
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53409
was published
Nov 7, 2025
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Consul event endpoint is vulnerable to denial of service
Moderate
CVE-2025-11375
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Consul key/value endpoint is vulnerable to denial of service
Moderate
CVE-2025-11374
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
An attacker that gains SSH access to an unprivileged account may be able to disrupt services ...
Moderate
Unreviewed
CVE-2025-59459
was published
Oct 27, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18...
Moderate
Unreviewed
CVE-2025-11974
was published
Oct 27, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-53069
was published
Oct 21, 2025
rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or...
Moderate
Unreviewed
CVE-2025-62672
was published
Oct 19, 2025
Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation...
Moderate
Unreviewed
CVE-2025-62666
was published
Oct 18, 2025
ProTip!
Advisories are also available from the
GraphQL API