GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,884
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,207
NuGet
743
pip
3,979
Pub
12
RubyGems
947
Rust
1,034
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,252 advisories
Filter by severity
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources...
High
Unreviewed
CVE-2025-11362
was published
Oct 7, 2025
A user with the appropriate authorization can create any number of user accounts via an API ...
Low
Unreviewed
CVE-2025-58578
was published
Oct 6, 2025
If a user tries to login but the provided credentials are incorrect a log is created. The data...
Moderate
Unreviewed
CVE-2025-58582
was published
Oct 6, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44012
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-33039
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-33040
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44006
was published
Oct 3, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-44007
was published
Oct 3, 2025
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High
CVE-2025-61595
was published
for
github.com/MANTRA-Chain/mantrachain
(Go)
Sep 30, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by...
Moderate
Unreviewed
CVE-2025-36099
was published
Sep 29, 2025
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10...
High
Unreviewed
CVE-2025-8014
was published
Sep 27, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7,...
Moderate
Unreviewed
CVE-2025-11042
was published
Sep 26, 2025
An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3,...
High
Unreviewed
CVE-2025-10858
was published
Sep 26, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10867
was published
Sep 26, 2025
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
High
CVE-2025-59830
was published
for
rack
(RubyGems)
Sep 25, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-8396
was published
for
go.temporal.io/server
(Go)
Sep 15, 2025
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a...
High
Unreviewed
CVE-2025-59375
was published
Sep 15, 2025
IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00...
Moderate
Unreviewed
CVE-2025-36035
was published
Sep 14, 2025
Hono has Body Limit Middleware Bypass
Moderate
CVE-2025-59139
was published
for
hono
(npm)
Sep 12, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2...
Moderate
Unreviewed
CVE-2025-1250
was published
Sep 12, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2...
Moderate
Unreviewed
CVE-2025-7337
was published
Sep 12, 2025
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote...
Moderate
Unreviewed
CVE-2024-45669
was published
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API