GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,615 advisories
Filter by severity
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence...
High
Unreviewed
CVE-2025-48615
was published
Dec 8, 2025
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service...
High
Unreviewed
CVE-2025-48631
was published
Dec 8, 2025
In the Linux kernel, the following vulnerability has been resolved:
net: sched: fix memory leak...
High
Unreviewed
CVE-2021-47295
was published
May 21, 2024
Logrus is vulnerable to DoS when using Entry.Writer()
High
CVE-2025-65637
was published
for
github.com/sirupsen/logrus
(Go)
Dec 4, 2025
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause...
High
Unreviewed
CVE-2020-27827
was published
May 24, 2022
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
BACnet Test Server versions up to and including 1.01 contains a remote denial of service...
High
Unreviewed
CVE-2020-36872
was published
Nov 27, 2025
An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an...
High
Unreviewed
CVE-2025-51741
was published
Nov 25, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service ...
High
Unreviewed
CVE-2019-9674
was published
May 24, 2022
Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an...
High
Unreviewed
CVE-2025-11681
was published
Nov 17, 2025
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command
High
CVE-2018-21258
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
A vulnerability in the web-based management interface of affected products could allow an...
High
Unreviewed
CVE-2025-37161
was published
Nov 18, 2025
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
High
CVE-2024-0241
was published
for
encoded_id-rails
(RubyGems)
Oct 24, 2023
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
High
CVE-2025-62260
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in...
High
Unreviewed
CVE-2021-4467
was published
Nov 15, 2025
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2...
High
Unreviewed
CVE-2021-4465
was published
Nov 15, 2025
jose2go is vulnerable to a JWT bomb attack through its decode function
High
CVE-2025-63811
was published
for
github.com/dvsekhvalnov/jose2go
(Go)
Nov 12, 2025
The Epson Stylus SX510W embedded web management service fails to properly handle consecutive...
High
Unreviewed
CVE-2023-7326
was published
Nov 13, 2025
In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in...
High
Unreviewed
CVE-2025-63288
was published
Nov 10, 2025
An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows...
High
Unreviewed
CVE-2025-63560
was published
Nov 6, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
High
CVE-2025-5115
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Aug 20, 2025
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem. Mishandling...
High
Unreviewed
CVE-2025-49494
was published
Nov 4, 2025
ProTip!
Advisories are also available from the
GraphQL API