GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,936 advisories
Filter by severity
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid...
High
Unreviewed
CVE-2025-57614
was published
Sep 10, 2025
A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software...
High
Unreviewed
CVE-2025-20340
was published
Sep 10, 2025
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated...
Moderate
Unreviewed
CVE-2025-49460
was published
Sep 10, 2025
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity
High
CVE-2025-58451
was published
for
cattown
(npm)
Sep 9, 2025
An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a...
High
Unreviewed
CVE-2025-52322
was published
Sep 9, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
Low
Unreviewed
CVE-2025-40802
was published
Sep 9, 2025
Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the...
High
Unreviewed
CVE-2025-52288
was published
Sep 8, 2025
Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due...
High
Unreviewed
CVE-2025-52494
was published
Sep 8, 2025
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
In multiple locations, there is a possible permanent denial of service due to resource exhaustion...
Moderate
Unreviewed
CVE-2025-26449
was published
Sep 5, 2025
In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding...
Moderate
Unreviewed
CVE-2025-26463
was published
Sep 5, 2025
In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an...
Moderate
Unreviewed
CVE-2024-40664
was published
Sep 4, 2025
In multiple functions of AccountManagerService.java, there is a possible permanent denial of...
Moderate
Unreviewed
CVE-2025-48542
was published
Sep 4, 2025
In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a...
Moderate
Unreviewed
CVE-2025-26423
was published
Sep 4, 2025
Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin
High
CVE-2025-43772
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 4, 2025
A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown...
Moderate
Unreviewed
CVE-2025-9670
was published
Aug 29, 2025
gnark affected by denial of service when computing scalar multiplication using fake-GLV algorithm
High
CVE-2025-58157
was published
for
github.com/consensys/gnark
(Go)
Aug 29, 2025
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If...
Moderate
Unreviewed
CVE-2025-29898
was published
Aug 29, 2025
In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead...
Moderate
Unreviewed
CVE-2024-49740
was published
Aug 27, 2025
GraphQL Armor Max-Depth Plugin Bypass via fragment caching
Moderate
GHSA-224p-v68g-5g8f
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
GraphQL Armor Max-Depth Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-hmfr-rx46-4jx2
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video...
High
Unreviewed
CVE-2025-55634
was published
Aug 22, 2025
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was...
High
Unreviewed
CVE-2025-55631
was published
Aug 22, 2025
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2025-9341
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API