GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,318
Maven
5,000+
npm
3,950
NuGet
711
pip
3,730
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
63 advisories
Filter by severity
quic-go Has Panic in Path Probe Loss Recovery Handling
High
CVE-2025-29785
was published
for
github.com/quic-go/quic-go
(Go)
Jun 3, 2025
Multer vulnerable to Denial of Service from maliciously crafted requests
High
CVE-2025-47944
was published
for
multer
(npm)
May 19, 2025
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user...
High
Unreviewed
CVE-2025-23166
was published
May 19, 2025
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
High
GHSA-rq86-9m6r-cm3g
was published
for
surrealdb
(Rust)
Apr 10, 2025
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This...
High
Unreviewed
CVE-2025-20664
was published
Apr 7, 2025
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework
Impact:...
High
Unreviewed
CVE-2024-58111
was published
Apr 7, 2025
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework
Impact:...
High
Unreviewed
CVE-2024-58112
was published
Apr 7, 2025
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This...
High
Unreviewed
CVE-2025-20663
was published
Apr 7, 2025
Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command...
High
Unreviewed
CVE-2025-3083
was published
Apr 1, 2025
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS...
High
Unreviewed
CVE-2024-8249
was published
Mar 20, 2025
PyTorch Lightning denial of service vulnerability
High
CVE-2024-8020
was published
for
pytorch-lightning
(pip)
Mar 20, 2025
Formwork improperly validates input of User role preventing site and panel availability
High
GHSA-c85w-x26q-ch87
was published
for
getformwork/formwork
(Composer)
Mar 1, 2025
Uncaught Panic in ORML Rewards Pallet
High
GHSA-5v93-9mqw-p9mh
was published
for
orml-rewards
(Rust)
Feb 14, 2025
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow...
High
Unreviewed
CVE-2025-20176
was published
Feb 5, 2025
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow...
High
Unreviewed
CVE-2025-20173
was published
Feb 5, 2025
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS...
High
Unreviewed
CVE-2025-20172
was published
Feb 5, 2025
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow...
High
Unreviewed
CVE-2025-20171
was published
Feb 5, 2025
In network HW, there is a possible system hang due to an uncaught exception. This could lead to...
High
Unreviewed
CVE-2025-20637
was published
Feb 3, 2025
Null pointer dereference vulnerability in the image decoding module
Impact: Successful...
High
Unreviewed
CVE-2024-54106
was published
Dec 12, 2024
rPGP Panics on Malformed Untrusted Input
High
CVE-2024-53856
was published
for
pgp
(Rust)
Dec 5, 2024
In wlan driver, there is a possible client disconnection due to improper handling of exceptional...
High
Unreviewed
CVE-2024-20137
was published
Dec 2, 2024
SurrealDB has an Uncaught Exception Handling Parsing Errors on Empty Strings
High
GHSA-qjrv-v6qp-x99x
was published
for
surrealdb
(Rust)
Oct 8, 2024
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
High
CVE-2024-43367
was published
for
boa_engine
(Rust)
Aug 14, 2024
Panic when parsing invalid palette-color images in golang.org/x/image
High
CVE-2024-24792
was published
for
golang.org/x/image
(Go)
Jun 26, 2024
ProTip!
Advisories are also available from the
GraphQL API