GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,362
Erlang
33
GitHub Actions
22
Go
2,134
Maven
5,000+
npm
3,797
NuGet
687
pip
3,473
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,066 advisories
Filter by severity
A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11...
Moderate
Unreviewed
CVE-2023-0921
was published
Jun 6, 2023
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series...
Moderate
Unreviewed
CVE-2024-20502
was published
Oct 2, 2024
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series...
Moderate
Unreviewed
CVE-2024-20500
was published
Oct 2, 2024
A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected...
Moderate
Unreviewed
CVE-2024-9358
was published
Oct 1, 2024
Denial of service attack via push rule patterns in matrix-synapse
Moderate
CVE-2021-29471
was published
for
matrix-synapse
(pip)
May 13, 2021
Denial of service attack via .well-known lookups
Moderate
CVE-2021-21274
was published
for
matrix-synapse
(pip)
Mar 1, 2021
The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain...
Moderate
Unreviewed
CVE-2024-8454
was published
Sep 30, 2024
The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to...
Moderate
Unreviewed
CVE-2024-30218
was published
Apr 9, 2024
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Moderate
CVE-2024-47003
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Sep 26, 2024
Spring Framework DoS via conditional HTTP request
Moderate
CVE-2024-38809
was published
for
org.springframework:spring-web
(Maven)
Sep 24, 2024
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom...
Moderate
Unreviewed
CVE-2023-39203
was published
Nov 15, 2023
Denial of service in rocket chat message parser
Moderate
CVE-2024-46935
was published
for
@rocket.chat/message-parser
(npm)
Sep 25, 2024
Strapi's field level permissions not being respected in relationship title
Moderate
CVE-2023-37263
was published
for
@strapi/plugin-content-manager
(npm)
Sep 13, 2023
Due to an allocation of resources without limits, an uncontrolled resource consumption...
Moderate
Unreviewed
CVE-2023-51393
was published
Feb 23, 2024
A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be...
Moderate
Unreviewed
CVE-2024-0240
was published
Feb 15, 2024
An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows...
Moderate
Unreviewed
CVE-2020-24089
was published
Sep 20, 2023
A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an...
Moderate
Unreviewed
CVE-2023-2683
was published
Jun 15, 2023
Regular Expression Denial of Service (ReDoS) in Jinja2
Moderate
CVE-2020-28493
was published
for
jinja2
(pip)
Mar 19, 2021
Sydent DoS (via resource exhaustion) due to improper input validation
Moderate
CVE-2021-29433
was published
for
matrix-sydent
(pip)
Apr 16, 2021
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Moderate
CVE-2021-21419
was published
for
eventlet
(pip)
May 7, 2021
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
Moderate
CVE-2023-41164
was published
for
django
(pip)
Nov 3, 2023
A
segmentation fault can occur in Brocade Fabric OS after Brocade Fabric
OS v9.0 and before...
Moderate
Unreviewed
CVE-2023-4162
was published
Aug 31, 2023
Django is vulnerable to Denial of Service attack in formset
Moderate
CVE-2013-0306
was published
for
Django
(pip)
May 5, 2022
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify...
Moderate
Unreviewed
CVE-2024-8892
was published
Sep 18, 2024
vLLM Denial of Service via the best_of parameter
Moderate
CVE-2024-8939
was published
for
vllm
(pip)
Sep 17, 2024
ProTip!
Advisories are also available from the
GraphQL API