GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,483
Maven
5,000+
npm
4,104
NuGet
734
pip
3,917
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,923 advisories
Filter by severity
A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and...
Moderate
Unreviewed
CVE-2025-6365
was published
Jun 20, 2025
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic...
Moderate
Unreviewed
CVE-2025-6274
was published
Jun 19, 2025
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory...
High
Unreviewed
CVE-2025-49763
was published
Jun 19, 2025
A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This...
Moderate
Unreviewed
CVE-2025-6140
was published
Jun 17, 2025
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
High
CVE-2025-3526
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Jun 16, 2025
Liferay Portal does not limit the depth of a GraphQL queries
High
CVE-2025-3602
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Jun 16, 2025
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an...
High
Unreviewed
CVE-2025-33068
was published
Jun 10, 2025
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS)...
High
Unreviewed
CVE-2025-32724
was published
Jun 10, 2025
CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of...
High
Unreviewed
CVE-2025-3112
was published
Jun 10, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects...
Moderate
Unreviewed
CVE-2025-5895
was published
Jun 9, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects...
Moderate
Unreviewed
CVE-2025-5890
was published
Jun 9, 2025
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1....
Moderate
Unreviewed
CVE-2025-5892
was published
Jun 9, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
Authorino Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-25208
was published
for
github.com/kuadrant/authorino
(Go)
Jun 9, 2025
Authorino Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-25207
was published
for
github.com/kuadrant/authorino
(Go)
Jun 9, 2025
Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04....
High
Unreviewed
CVE-2025-41361
was published
Jun 6, 2025
Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04....
High
Unreviewed
CVE-2025-41360
was published
Jun 6, 2025
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service ...
Moderate
Unreviewed
CVE-2024-53423
was published
May 29, 2025
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections,...
High
Unreviewed
CVE-2025-5024
was published
May 22, 2025
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Low
CVE-2025-5031
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest...
Moderate
Unreviewed
CVE-2025-41226
was published
May 20, 2025
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain...
Moderate
Unreviewed
CVE-2025-41227
was published
May 20, 2025
ProTip!
Advisories are also available from the
GraphQL API