GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
25 advisories
Filter by severity
IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local...
Low
Unreviewed
CVE-2026-18096
was published
Aug 12, 2026
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default...
Low
Unreviewed
CVE-2025-71396
was published
Jul 18, 2026
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource...
Low
Unreviewed
CVE-2026-60000
was published
Jul 8, 2026
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest...
Low
Unreviewed
CVE-2026-13322
was published
Jun 26, 2026
An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2...
Low
Unreviewed
CVE-2026-44070
was published
May 21, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2026-22018
was published
Apr 21, 2026
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an...
Low
Unreviewed
CVE-2025-66487
was published
Apr 2, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-57711
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-58471
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-54161
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-54155
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-57710
was published
Feb 11, 2026
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-57708
was published
Feb 11, 2026
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a...
Low
Unreviewed
CVE-2025-1823
was published
Feb 4, 2026
Interactive service agent in OpenVPN version 2.5.0 through 2.7_rc2 on Windows allows a local...
Low
Unreviewed
CVE-2025-13751
was published
Dec 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-53411
was published
Nov 7, 2025
A user with the appropriate authorization can create any number of user accounts via an API ...
Low
Unreviewed
CVE-2025-58578
was published
Oct 6, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10867
was published
Sep 26, 2025
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC...
Low
Unreviewed
CVE-2025-40570
was published
Aug 12, 2025
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are...
Low
Unreviewed
CVE-2024-21174
was published
Jul 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21011
was published
Apr 17, 2024
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server...
Low
Unreviewed
CVE-2024-3302
was published
Apr 16, 2024
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow.
Low
Unreviewed
CVE-2024-29086
was published
Apr 2, 2024
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9...
Low
Unreviewed
CVE-2023-5963
was published
Nov 6, 2023
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd)...
Low
Unreviewed
CVE-2020-10717
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API