GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,479
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
Kwik hash collision vulnerability
Moderate
CVE-2025-23020
was published
for
tech.kwik:kwik
(Maven)
Feb 20, 2025
A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka...
Moderate
Unreviewed
CVE-2025-24947
was published
Feb 20, 2025
The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function,...
Moderate
Unreviewed
CVE-2025-24946
was published
Feb 20, 2025
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a...
Moderate
Unreviewed
CVE-2024-12133
was published
Feb 10, 2025
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an...
Moderate
Unreviewed
CVE-2024-12243
was published
Feb 10, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9...
High
Unreviewed
CVE-2024-9631
was published
Feb 5, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5...
Moderate
Unreviewed
CVE-2024-6324
was published
Jan 9, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5...
High
Unreviewed
CVE-2024-8233
was published
Dec 12, 2024
league/commonmark's quadratic complexity bugs may lead to a denial of service
High
GHSA-c2pc-g5qf-rfrf
was published
for
league/commonmark
(Composer)
Dec 9, 2024
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior...
Moderate
Unreviewed
CVE-2024-8237
was published
Nov 26, 2024
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5...
Moderate
Unreviewed
CVE-2024-8177
was published
Nov 26, 2024
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13...
Moderate
Unreviewed
CVE-2024-11828
was published
Nov 26, 2024
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco ...
Moderate
Unreviewed
CVE-2020-3548
was published
Nov 18, 2024
Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability
High
CVE-2024-43485
was published
for
System.Text.Json
(NuGet)
Oct 8, 2024
Microsoft Security Advisory CVE-2024-43484 | .NET Denial of Service Vulnerability
High
CVE-2024-43484
was published
for
System.IO.Packaging
(NuGet)
Oct 8, 2024
Microsoft Security Advisory CVE-2024-43483 | .NET Denial of Service Vulnerability
High
CVE-2024-43483
was published
for
Microsoft.Extensions.Caching.Memory
(NuGet)
Oct 8, 2024
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during...
Moderate
Unreviewed
CVE-2024-39702
was published
Jul 23, 2024
The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock...
Moderate
Unreviewed
CVE-2024-29916
was published
Mar 21, 2024
Inefficient Algorithmic Complexity in com.upokecenter:cbor
High
CVE-2024-23684
was published
for
com.upokecenter:cbor
(Maven)
Jan 19, 2024
Duplicate Advisory: Denial of service in CBOR library
High
GHSA-hf3r-vmrv-7w29
was published
for
PeterO.Cbor
(NuGet)
Jan 3, 2024
•
withdrawn
Several quadratic complexity bugs may lead to denial of service in Commonmarker
Moderate
GHSA-7vh7-fw88-wj87
was published
for
commonmarker
(RubyGems)
Aug 8, 2023
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
High
Unreviewed
CVE-2023-38285
was published
Jul 26, 2023
PyPDF2 quadratic runtime with malformed PDF missing xref marker
Moderate
CVE-2023-36810
was published
for
PyPDF2
(pip)
Jun 30, 2023
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This...
Moderate
Unreviewed
CVE-2023-2473
was published
May 2, 2023
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one...
High
Unreviewed
CVE-2022-45061
was published
Nov 9, 2022
ProTip!
Advisories are also available from the
GraphQL API