GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
41 advisories
Filter by severity
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18...
Low
Unreviewed
CVE-2025-12983
was published
Nov 15, 2025
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX...
Moderate
Unreviewed
CVE-2025-2534
was published
Nov 7, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could...
High
Unreviewed
CVE-2025-23331
was published
Aug 6, 2025
IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server...
Moderate
Unreviewed
CVE-2025-2533
was published
Jul 29, 2025
Redis through 7.4.3 allows memory consumption via a multi-bulk command composed of many bulks,...
Moderate
Unreviewed
CVE-2025-46686
was published
Jul 23, 2025
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled...
Moderate
Unreviewed
CVE-2025-4605
was published
Jun 11, 2025
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1...
Moderate
Unreviewed
CVE-2025-2518
was published
May 29, 2025
IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial...
High
Unreviewed
CVE-2025-3632
was published
May 12, 2025
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for...
High
Unreviewed
CVE-2025-20140
was published
May 7, 2025
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48...
Moderate
Unreviewed
CVE-2025-29491
was published
Mar 27, 2025
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an...
High
Unreviewed
CVE-2025-20165
was published
Jan 22, 2025
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could...
Moderate
Unreviewed
CVE-2024-37071
was published
Dec 7, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-41762
was published
Dec 7, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is...
Moderate
Unreviewed
CVE-2024-41761
was published
Nov 23, 2024
A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series...
Moderate
Unreviewed
CVE-2022-20845
was published
Nov 15, 2024
A vulnerability in the VPN and management web servers of the Cisco Adaptive Security Virtual...
High
Unreviewed
CVE-2024-20260
was published
Oct 23, 2024
IBM MQ Operator 2.0.26 and 3.2.4 could allow a local user to cause a denial of service due to...
Moderate
Unreviewed
CVE-2024-40680
was published
Sep 7, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an...
Moderate
Unreviewed
CVE-2024-35152
was published
Aug 14, 2024
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 could allow an...
Moderate
Unreviewed
CVE-2024-37529
was published
Aug 14, 2024
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack...
Moderate
Unreviewed
CVE-2024-35116
was published
Jun 29, 2024
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code...
Moderate
Unreviewed
CVE-2024-2494
was published
Mar 21, 2024
To keep its cache database efficient, `named` running as a recursive resolver occasionally...
High
Unreviewed
CVE-2023-6516
was published
Feb 13, 2024
dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in...
Moderate
Unreviewed
CVE-2023-52429
was published
Feb 12, 2024
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation...
High
Unreviewed
CVE-2023-3171
was published
Dec 27, 2023
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom...
Moderate
Unreviewed
CVE-2023-39203
was published
Nov 15, 2023
ProTip!
Advisories are also available from the
GraphQL API