GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,792
Erlang
36
GitHub Actions
29
Go
2,377
Maven
5,000+
npm
4,002
NuGet
720
pip
3,802
Pub
12
RubyGems
927
Rust
984
Swift
38
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
Moderate
CVE-2025-3044
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions)....
Moderate
Unreviewed
CVE-2025-40555
was published
May 13, 2025
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the...
Moderate
Unreviewed
CVE-2025-32728
was published
Apr 10, 2025
SageMaker Workflow component allows possibility of MD5 hash collisions
Moderate
CVE-2025-0508
was published
for
sagemaker
(pip)
Mar 20, 2025
Expected Behavior Violation vulnerability in Apache Traffic Server.
This issue affects Apache...
Moderate
Unreviewed
CVE-2024-56202
was published
Mar 6, 2025
Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend
Moderate
CVE-2024-47762
was published
for
@backstage/plugin-app-backend
(npm)
Oct 3, 2024
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2024-8690
was published
Sep 11, 2024
It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table...
Moderate
Unreviewed
CVE-2024-7246
was published
Aug 6, 2024
Unauthenticated Nonce Increment in snow
Moderate
GHSA-7g9j-g5jg-3vv3
was published
for
snow
(Rust)
Jan 24, 2024
Issue summary: The POLY1305 MAC (message authentication code) implementation
contains a bug that...
Moderate
Unreviewed
CVE-2023-6129
was published
Jan 9, 2024
gRPC connection termination issue
Moderate
CVE-2023-32732
was published
for
grpc
(RubyGems)
Jul 6, 2023
A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be...
Moderate
Unreviewed
CVE-2023-2088
was published
May 12, 2023
A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could...
Moderate
Unreviewed
CVE-2022-3344
was published
Oct 25, 2022
WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller...
Moderate
Unreviewed
CVE-2022-3281
was published
Oct 17, 2022
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for...
Moderate
Unreviewed
CVE-2019-5062
was published
May 24, 2022
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could...
Moderate
Unreviewed
CVE-2019-5061
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API