GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,840
Erlang
36
GitHub Actions
33
Go
2,464
Maven
5,000+
npm
4,082
NuGet
723
pip
3,880
Pub
12
RubyGems
943
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
132 advisories
Filter by severity
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A...
High
Unreviewed
CVE-2013-10065
was published
Aug 5, 2025
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote,...
Moderate
Unreviewed
CVE-2025-3891
was published
Apr 29, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Multer vulnerable to Denial of Service via unhandled exception from malformed request
High
CVE-2025-7338
was published
for
multer
(npm)
Jul 17, 2025
Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests
Critical
CVE-2025-53620
was published
for
@builder.io/qwik-city
(npm)
Jul 9, 2025
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
High
CVE-2025-53366
was published
for
mcp
(pip)
Jul 4, 2025
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
High
CVE-2025-53365
was published
for
mcp
(pip)
Jul 4, 2025
vLLM allows clients to crash the openai server with invalid regex
Moderate
CVE-2025-48943
was published
for
vllm
(pip)
May 28, 2025
vLLM DOS: Remotely kill vllm over http with invalid JSON schema
Moderate
CVE-2025-48942
was published
for
vllm
(pip)
May 28, 2025
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if
exploited, could...
High
Unreviewed
CVE-2025-44019
was published
Jun 12, 2025
AVEVA PI Data Archive products
are vulnerable to an uncaught exception that, if exploited, could...
High
Unreviewed
CVE-2025-36539
was published
Jun 12, 2025
Deserialization vulnerability in the IPC module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2025-48907
was published
Jun 6, 2025
Multer vulnerable to Denial of Service via unhandled exception
High
CVE-2025-48997
was published
for
multer
(npm)
Jun 5, 2025
quic-go Has Panic in Path Probe Loss Recovery Handling
High
CVE-2025-29785
was published
for
github.com/quic-go/quic-go
(Go)
Jun 3, 2025
Elasticsearch Uncaught Exception leading to crash
Moderate
CVE-2024-23449
was published
for
org.elasticsearch:elasticsearch
(Maven)
Mar 29, 2024
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability...
Moderate
Unreviewed
CVE-2024-0754
was published
Jan 23, 2024
Multer vulnerable to Denial of Service from maliciously crafted requests
High
CVE-2025-47944
was published
for
multer
(npm)
May 19, 2025
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user...
High
Unreviewed
CVE-2025-23166
was published
May 19, 2025
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an...
Moderate
Unreviewed
CVE-2025-20054
was published
May 13, 2025
In F?Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022...
High
Unreviewed
CVE-2022-38166
was published
Nov 25, 2022
Keylime: unhandled exceptions could lead to invalid attestation states
High
CVE-2022-3500
was published
for
Keylime
(pip)
Oct 28, 2022
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting...
High
Unreviewed
CVE-2016-10363
was published
May 13, 2022
The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning...
Moderate
Unreviewed
CVE-2025-32944
was published
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API