GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
975
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an...
High
Unreviewed
CVE-2025-59174
was published
Jun 5, 2026
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of...
High
Unreviewed
CVE-2026-25657
was published
Jun 5, 2026
Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of...
High
Unreviewed
CVE-2026-42100
was published
May 19, 2026
Ericsson Packet Core Controller (PCC) versions prior
to 1.38 contain a vulnerability where an...
Moderate
Unreviewed
CVE-2024-53828
was published
Apr 1, 2026
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software...
High
Unreviewed
CVE-2026-20125
was published
Mar 25, 2026
Applications using affected versions of Ehcache 3.x can experience degraded cache-write...
Low
Unreviewed
CVE-2025-2529
was published
Oct 15, 2025
CometBFT's invalid BitArray handling can lead to network halt
High
GHSA-hrhf-2vcr-ghch
was published
for
github.com/cometbft/cometbft
(Go)
Oct 14, 2025
libsql-sqlite3-parser crash due to invalid UTF-8 input
Low
CVE-2025-47736
was published
for
libsql-sqlite3-parser
(Rust)
May 9, 2025
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7...
Moderate
Unreviewed
CVE-2024-55594
was published
Mar 14, 2025
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4...
Moderate
Unreviewed
CVE-2023-42784
was published
Mar 11, 2025
CVE-2025-0343: Swift ASN.1 can crash when parsing maliciously formed BER/DER
Low
CVE-2025-0343
was published
for
github.com/apple/swift-asn1
(Swift)
Jan 14, 2025
MongoDB Rust driver may issue unintended commands
Moderate
CVE-2024-6382
was published
for
mongodb
(Rust)
Jul 2, 2024
Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows...
Moderate
Unreviewed
CVE-2024-22809
was published
Apr 22, 2024
An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6...
Moderate
Unreviewed
CVE-2024-22815
was published
Apr 22, 2024
An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding...
High
Unreviewed
CVE-2024-21612
was published
Jan 12, 2024
NLnet Labs’ Routinator up to and including version 0.12.1 may crash when trying to parse certain...
High
Unreviewed
CVE-2023-39915
was published
Sep 13, 2023
BER/CER/DER decoder panics on invalid input
High
CVE-2023-39914
was published
for
bcder
(Rust)
Sep 13, 2023
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow...
Critical
Unreviewed
CVE-2021-38443
was published
May 6, 2022
Authentication Bypass in dex
Critical
CVE-2020-27847
was published
for
github.com/dexidp/dex
(Go)
Dec 20, 2021
ProTip!
Advisories are also available from the
GraphQL API