GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,820 advisories
Filter by severity
A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected...
Moderate
Unreviewed
CVE-2025-6492
was published
Jun 22, 2025
A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and...
Moderate
Unreviewed
CVE-2025-6365
was published
Jun 20, 2025
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic...
Moderate
Unreviewed
CVE-2025-6274
was published
Jun 19, 2025
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory...
High
Unreviewed
CVE-2025-49763
was published
Jun 19, 2025
A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This...
Moderate
Unreviewed
CVE-2025-6140
was published
Jun 17, 2025
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
High
CVE-2025-3526
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Jun 16, 2025
Liferay Portal does not limit the depth of a GraphQL queries
High
CVE-2025-3602
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Jun 16, 2025
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an...
High
Unreviewed
CVE-2025-33068
was published
Jun 10, 2025
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS)...
High
Unreviewed
CVE-2025-32724
was published
Jun 10, 2025
CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of...
High
Unreviewed
CVE-2025-3112
was published
Jun 10, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1....
Moderate
Unreviewed
CVE-2025-5892
was published
Jun 9, 2025
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects...
Moderate
Unreviewed
CVE-2025-5890
was published
Jun 9, 2025
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects...
Moderate
Unreviewed
CVE-2025-5895
was published
Jun 9, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
Authorino Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-25208
was published
for
github.com/kuadrant/authorino
(Go)
Jun 9, 2025
Authorino Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-25207
was published
for
github.com/kuadrant/authorino
(Go)
Jun 9, 2025
Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04....
High
Unreviewed
CVE-2025-41361
was published
Jun 6, 2025
Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04....
High
Unreviewed
CVE-2025-41360
was published
Jun 6, 2025
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service ...
Moderate
Unreviewed
CVE-2024-53423
was published
May 29, 2025
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections,...
High
Unreviewed
CVE-2025-5024
was published
May 22, 2025
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Low
CVE-2025-5031
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain...
Moderate
Unreviewed
CVE-2025-41227
was published
May 20, 2025
ProTip!
Advisories are also available from the
GraphQL API