GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
765
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,550 advisories
Filter by severity
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service...
High
Unreviewed
CVE-2025-48631
was published
Dec 8, 2025
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence...
High
Unreviewed
CVE-2025-48615
was published
Dec 8, 2025
Logrus is vulnerable to DoS when using Entry.Writer()
High
CVE-2025-65637
was published
for
github.com/sirupsen/logrus
(Go)
Dec 4, 2025
BACnet Test Server versions up to and including 1.01 contains a remote denial of service...
High
Unreviewed
CVE-2020-36872
was published
Nov 27, 2025
An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an...
High
Unreviewed
CVE-2025-51741
was published
Nov 25, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
A vulnerability in the web-based management interface of affected products could allow an...
High
Unreviewed
CVE-2025-37161
was published
Nov 18, 2025
Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an...
High
Unreviewed
CVE-2025-11681
was published
Nov 17, 2025
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2...
High
Unreviewed
CVE-2021-4465
was published
Nov 15, 2025
Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in...
High
Unreviewed
CVE-2021-4467
was published
Nov 15, 2025
The Epson Stylus SX510W embedded web management service fails to properly handle consecutive...
High
Unreviewed
CVE-2023-7326
was published
Nov 13, 2025
jose2go is vulnerable to a JWT bomb attack through its decode function
High
CVE-2025-63811
was published
for
github.com/dvsekhvalnov/jose2go
(Go)
Nov 12, 2025
In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in...
High
Unreviewed
CVE-2025-63288
was published
Nov 10, 2025
An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows...
High
Unreviewed
CVE-2025-63560
was published
Nov 6, 2025
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem. Mishandling...
High
Unreviewed
CVE-2025-49494
was published
Nov 4, 2025
The issue was addressed with improved memory handling. This issue is fixed in watchOS 26.1, iOS...
High
Unreviewed
CVE-2025-43462
was published
Nov 4, 2025
The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS...
High
Unreviewed
CVE-2025-43424
was published
Nov 4, 2025
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in...
High
Unreviewed
CVE-2025-43385
was published
Nov 4, 2025
Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a...
High
Unreviewed
CVE-2025-63561
was published
Oct 31, 2025
Malicious or unintentional API requests can be used to add significant amount of data to caches....
High
Unreviewed
CVE-2025-30188
was published
Oct 31, 2025
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This...
High
Unreviewed
CVE-2025-10932
was published
Oct 29, 2025
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
High
CVE-2025-62727
was published
for
starlette
(pip)
Oct 28, 2025
ProTip!
Advisories are also available from the
GraphQL API