GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      42 advisories
        Filter by severity
        
      
      
    
                    
                      If the value passed to os.path.expandvars() is user-controlled a 
performance degradation is...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6075
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-40802
                      
                      was published
                      Sep 9, 2025 
                    
                  
                    
                      Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27576
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50104
                      
                      was published
                      Jul 15, 2025 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50100
                      
                      was published
                      Jul 15, 2025 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50098
                      
                      was published
                      Jul 15, 2025 
                    
                  
                    
                      Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component:...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30752
                      
                      was published
                      Jul 15, 2025 
                    
                  
                    
                      Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20616
                      
                      was published
                      May 13, 2025 
                    
                  
                    
                      A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4215
                      
                      was published
                      May 2, 2025 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30681
                      
                      was published
                      Apr 15, 2025 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-21232
                      
                      was published
                      Oct 15, 2024 
                    
                  
                    
                      Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-21231
                      
                      was published
                      Oct 15, 2024 
                    
                  
                    
                      A denial-of-service vulnerability could allow an authenticated user to trigger an internal...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4003
                      
                      was published
                      Jul 31, 2024 
                    
                  
                    
                      A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-6501
                      
                      was published
                      Jul 9, 2024 
                    
                  
                    
                      A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-6126
                      
                      was published
                      Jul 3, 2024 
                    
                  
                    
                      DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-5469
                      
                      was published
                      Jun 14, 2024 
                    
                  
                    
                      Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-3872
                      
                      was published
                      Apr 16, 2024 
                    
                  
                    
                      Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-24975
                      
                      was published
                      Mar 15, 2024 
                    
                  
                    
                      nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-28214
                      
                      was published
                      Mar 7, 2024 
                    
                  
                    
                      SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-49578
                      
                      was published
                      Dec 12, 2023 
                    
                  
                    
                      A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5870
                      
                      was published
                      Dec 10, 2023 
                    
                  
                    
                      Mattermost fails to properly validate a RegExp built off the server URL path, allowing an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5876
                      
                      was published
                      Nov 2, 2023 
                    
                  
                    
                      Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-41310
                      
                      was published
                      Sep 27, 2023 
                    
                  
                    
                      Mattermost fails to properly validate a gif image file, allowing an attacker to consume a...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-3614
                      
                      was published
                      Jul 17, 2023 
                    
                  
                    
                      A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4952
                      
                      was published
                      Jul 17, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API