GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,102 advisories
Filter by severity
An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to...
High
Unreviewed
CVE-2025-60536
was published
Oct 14, 2025
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized...
High
Unreviewed
CVE-2025-59502
was published
Oct 14, 2025
A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an...
Moderate
Unreviewed
CVE-2025-37148
was published
Oct 14, 2025
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently...
Moderate
Unreviewed
CVE-2025-37139
was published
Oct 14, 2025
A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability...
Moderate
Unreviewed
CVE-2025-11635
was published
Oct 12, 2025
An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks...
High
Unreviewed
CVE-2025-59975
was published
Oct 9, 2025
An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM)...
High
Unreviewed
CVE-2025-52961
was published
Oct 9, 2025
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the...
Moderate
Unreviewed
CVE-2025-11274
was published
Oct 5, 2025
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If...
Moderate
Unreviewed
CVE-2025-52867
was published
Oct 3, 2025
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a...
High
Unreviewed
CVE-2025-55972
was published
Oct 3, 2025
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for...
Moderate
Unreviewed
CVE-2025-59403
was published
Oct 2, 2025
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2025-20370
was published
Oct 1, 2025
AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the...
High
Unreviewed
CVE-2025-56234
was published
Sep 29, 2025
Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP...
High
Unreviewed
CVE-2025-56233
was published
Sep 29, 2025
An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly...
High
Unreviewed
CVE-2024-57412
was published
Sep 29, 2025
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings...
High
Unreviewed
CVE-2025-55847
was published
Sep 26, 2025
An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set...
High
Unreviewed
CVE-2025-55559
was published
Sep 25, 2025
An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of...
High
Unreviewed
CVE-2025-55560
was published
Sep 25, 2025
A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d,...
High
Unreviewed
CVE-2025-55558
was published
Sep 25, 2025
An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote...
High
Unreviewed
CVE-2025-57446
was published
Sep 25, 2025
An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of...
High
Unreviewed
CVE-2025-55551
was published
Sep 25, 2025
The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which...
High
Unreviewed
CVE-2025-57440
was published
Sep 22, 2025
A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-4444
was published
Sep 18, 2025
CISA Thorium does not rate limit requests to send account verification email messages. A remote...
Moderate
Unreviewed
CVE-2025-35432
was published
Sep 17, 2025
The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.
High
Unreviewed
CVE-2025-56264
was published
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API