GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
815 advisories
Filter by severity
pyftpdlib vulnerable to allocation of resources without limits
High
CVE-2007-6740
was published
for
pyftpdlib
(pip)
May 1, 2022
Joomla! 1.03 does not restrict the number of "Search" Mambots, which allows remote attackers to...
Moderate
Unreviewed
CVE-2005-4650
was published
May 1, 2022
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote...
Moderate
Unreviewed
CVE-2005-2970
was published
May 1, 2022
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command...
Moderate
Unreviewed
CVE-2001-1388
was published
Apr 30, 2022
A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to...
High
Unreviewed
CVE-2022-29701
was published
Apr 28, 2022
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP...
High
Unreviewed
CVE-2022-22278
was published
Apr 28, 2022
encoding/pem in Go before 1.17.9 and 1.8.x before 1.8.1 has a Decode stack overflow via a large...
High
Unreviewed
CVE-2022-24675
was published
Apr 21, 2022
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with...
High
Unreviewed
CVE-2022-20622
was published
Apr 16, 2022
A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated...
Moderate
Unreviewed
CVE-2022-20717
was published
Apr 16, 2022
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using...
High
Unreviewed
CVE-2021-44502
was published
Apr 16, 2022
Resource exhaustion in Mattermost
Moderate
CVE-2022-1337
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Apr 14, 2022
Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number...
Moderate
Unreviewed
CVE-2022-1333
was published
Apr 14, 2022
Unsafe parsing in SWHKD
Moderate
CVE-2022-27819
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 8, 2022
A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14...
Moderate
Unreviewed
CVE-2022-1121
was published
Apr 5, 2022
Allocation of Resources Without Limits or Throttling in Spring Framework
Moderate
CVE-2022-22950
was published
for
org.springframework:spring-expression
(Maven)
Apr 3, 2022
IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified...
Moderate
Unreviewed
CVE-2022-22404
was published
Apr 2, 2022
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in WEKA INTEREST Security Scanner...
High
Unreviewed
CVE-2017-20016
was published
Mar 29, 2022
Allocation of Resources Without Limits or Throttling in nvflare
High
CVE-2022-21822
was published
for
nvflare
(pip)
Mar 18, 2022
Moodle denial-of-service risk in the draft files area
High
CVE-2021-32476
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
Moderate
CVE-2022-26336
was published
for
org.apache.poi:poi-scratchpad
(Maven)
Mar 5, 2022
Twisted SSH client and server deny of service during SSH handshake.
High
CVE-2022-21716
was published
for
twisted
(pip)
Mar 3, 2022
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling
High
CVE-2022-24685
was published
for
github.com/hashicorp/nomad
(Go)
Mar 1, 2022
Allocation of Resources Without Limits or Throttling in metadata-extractor
Moderate
CVE-2022-24614
was published
for
com.drewnoakes:metadata-extractor
(Maven)
Feb 25, 2022
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU...
High
Unreviewed
CVE-2016-20013
was published
Feb 20, 2022
Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote...
High
Unreviewed
CVE-2022-23228
was published
Feb 19, 2022
ProTip!
Advisories are also available from the
GraphQL API