GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            54 advisories
        Filter by severity
        
      
      
    
                    
                      Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8531
                      
                      was published
                      Sep 19, 2025 
                    
                  
                    
                      In multiple locations, there is a possible way to persistently DoS the device due to a missing...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-26432
                      
                      was published
                      Sep 5, 2025 
                    
                  
                    
                      Improper Handling of Length Parameter Inconsistency vulnerability in web server function on...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5514
                      
                      was published
                      Aug 25, 2025 
                    
                  
                    
                      Vulnerability of inadequate packet length check in the BLE module.
Impact: Successful...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54646
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      Duplicate Advisory: Remotely exploitable denial of service in Rosenpass
                    
                      
  Moderate
                    
                
                      
                        GHSA-624c-2h52-gf7f
                      
                      was published
                        for
                        
                          rosenpass
                        
                        (Rust)
                      Jul 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52949
                      
                      was published
                      Jul 11, 2025 
                    
                  
                    
                      Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53604
                      
                      was published
                        for
                        
                          web-push
                        
                        (Rust)
                      Jul 5, 2025 
                    
                  
                    
                      NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-23247
                      
                      was published
                      May 27, 2025 
                    
                  
                    
                      A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-29931
                      
                      was published
                      Apr 17, 2025 
                    
                  
                    
                      An Improper Handling of Length Parameter Inconsistency vulnerability in the Packet Forwarding...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30659
                      
                      was published
                      Apr 9, 2025 
                    
                  
                    
                      In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32366
                      
                      was published
                      Apr 7, 2025 
                    
                  
                    
                      rPGP Panics on Malformed Untrusted Input
                    
                      
  High
                    
                
                      
                        CVE-2024-53856
                      
                      was published
                        for
                        
                          pgp
                        
                        (Rust)
                      Dec 5, 2024 
                    
                  
                    
                      Out-of-bounds write vulnerability in the HAL-WIFI module
Impact: Successful exploitation of this...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-47293
                      
                      was published
                      Sep 27, 2024 
                    
                  
                    
                      Django vulnerable to denial-of-service attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-41991
                      
                      was published
                        for
                        
                          Django
                        
                        (pip)
                      Aug 7, 2024 
                    
                  
                    
                      Django vulnerable to a denial-of-service attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-41990
                      
                      was published
                        for
                        
                          Django
                        
                        (pip)
                      Aug 7, 2024 
                    
                  
                    
                      Elliptic's ECDSA missing check for whether leading bit of r and s is zero
                    
                      
  Low
                    
                
                      
                        CVE-2024-42460
                      
                      was published
                        for
                        
                          elliptic
                        
                        (npm)
                      Aug 2, 2024 
                    
                  
                    
                      A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-20416
                      
                      was published
                      Jul 17, 2024 
                    
                  
                    
                      Django vulnerable to Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2024-39614
                      
                      was published
                        for
                        
                          Django
                        
                        (pip)
                      Jul 10, 2024 
                    
                  
                    
                      Django vulnerable to Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2024-38875
                      
                      was published
                        for
                        
                          Django
                        
                        (pip)
                      Jul 10, 2024 
                    
                  
                    
                      Secure Boot Security Feature Bypass Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38010
                      
                      was published
                      Jul 9, 2024 
                    
                  
                    
                      Secure Boot Security Feature Bypass Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-37988
                      
                      was published
                      Jul 9, 2024 
                    
                  
                    
                      Secure Boot Security Feature Bypass Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-37989
                      
                      was published
                      Jul 9, 2024 
                    
                  
                    
                      Secure Boot Security Feature Bypass Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38011
                      
                      was published
                      Jul 9, 2024 
                    
                  
                    
                      Tor path lengths too short when "full Vanguards" configured
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-35313
                      
                      was published
                        for
                        
                          arti
                        
                        (Rust)
                      May 18, 2024 
                    
                  
                    
                      Server receiving a malformed message that causes a disconnect to a hostname may causing a stack...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5393
                      
                      was published
                      Apr 11, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API