GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
284 advisories
Filter by severity
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2023-30443
was published
Dec 19, 2024
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6,...
Moderate
Unreviewed
CVE-2024-9367
was published
Dec 12, 2024
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2,...
Moderate
Unreviewed
CVE-2024-54501
was published
Dec 12, 2024
In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper...
Moderate
Unreviewed
CVE-2018-9412
was published
Nov 20, 2024
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: check outstanding...
Moderate
Unreviewed
CVE-2024-50285
was published
Nov 19, 2024
In the Linux kernel, the following vulnerability has been resolved:
signal: restore the...
Moderate
Unreviewed
CVE-2024-50271
was published
Nov 19, 2024
In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific...
Moderate
Unreviewed
CVE-2024-52913
was published
Nov 18, 2024
Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis...
Moderate
Unreviewed
CVE-2024-52917
was published
Nov 18, 2024
Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2024-52918
was published
Nov 18, 2024
In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due...
Moderate
Unreviewed
CVE-2024-43083
was published
Nov 13, 2024
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of...
Moderate
Unreviewed
CVE-2024-21994
was published
Nov 8, 2024
A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7...
Moderate
Unreviewed
CVE-2024-10599
was published
Nov 1, 2024
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation...
Moderate
Unreviewed
CVE-2024-31152
was published
Oct 30, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4...
Moderate
Unreviewed
CVE-2024-6826
was published
Oct 24, 2024
A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow...
Moderate
Unreviewed
CVE-2024-20526
was published
Oct 23, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-31880
was published
Oct 23, 2024
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to...
Moderate
Unreviewed
CVE-2024-50311
was published
Oct 22, 2024
Improper resource management in firmware of some Solidigm DC Products may allow an attacker to...
Moderate
Unreviewed
CVE-2024-47969
was published
Oct 8, 2024
In the Linux kernel, the following vulnerability has been resolved:
nouveau/firmware: use dma...
Moderate
Unreviewed
CVE-2024-45012
was published
Sep 11, 2024
In the Linux kernel, the following vulnerability has been resolved:
s390/boot: Avoid possible...
Moderate
Unreviewed
CVE-2024-45014
was published
Sep 11, 2024
Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU...
Moderate
Unreviewed
CVE-2024-23184
was published
Sep 10, 2024
An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation...
Moderate
Unreviewed
CVE-2024-7734
was published
Sep 10, 2024
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API alwaysmulti.cgi...
Moderate
Unreviewed
CVE-2024-6509
was published
Sep 10, 2024
IBM MQ Operator 2.0.26 and 3.2.4 could allow a local user to cause a denial of service due to...
Moderate
Unreviewed
CVE-2024-40680
was published
Sep 7, 2024
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service...
Moderate
Unreviewed
CVE-2024-41175
was published
Aug 27, 2024
ProTip!
Advisories are also available from the
GraphQL API