GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
288,475 advisories
Filter by severity
Apache Tomcat Denial of Service via invalid HTTP priority header
Moderate
CVE-2025-31650
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Dec 17, 2024
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
High
CVE-2024-50379
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Dec 17, 2024
Apache Tomcat - Authentication Bypass
Critical
CVE-2024-52316
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Nov 18, 2024
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2024-38286
was published
for
org.apache.tomcat:tomcat-util
(Maven)
Nov 7, 2024
Apache Tomcat - Denial of Service
High
CVE-2024-34750
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jul 3, 2024
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Moderate
CVE-2024-23672
was published
for
org.apache.tomcat.embed:tomcat-embed-websocket
(Maven)
Mar 13, 2024
An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime...
Unknown
Unreviewed
CVE-2025-54950
was published
Aug 8, 2025
Student Attendance Management System v1 was discovered to contain multiple SQL injection...
High
Unreviewed
CVE-2023-41522
was published
Aug 7, 2025
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the...
High
Unreviewed
CVE-2025-47219
was published
Aug 7, 2025
In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past...
Moderate
Unreviewed
CVE-2025-47806
was published
Aug 7, 2025
The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress...
Moderate
Unreviewed
CVE-2025-6572
was published
Aug 8, 2025
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability...
High
Unreviewed
CVE-2023-41524
was published
Aug 7, 2025
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability...
High
Unreviewed
CVE-2023-41523
was published
Aug 7, 2025
Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability....
Critical
Unreviewed
CVE-2024-6246
was published
Nov 22, 2024
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure...
Moderate
Unreviewed
CVE-2025-20184
was published
Feb 5, 2025
Apache Tomcat Improper Input Validation vulnerability
High
CVE-2023-46589
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 28, 2023
A TLS vulnerability exists in the phone application used to manage a
connected device. The phone...
High
Unreviewed
CVE-2025-8393
was published
Aug 8, 2025
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external...
High
Unreviewed
CVE-2025-8355
was published
Aug 8, 2025
The affected product allows firmware updates to be downloaded from EG4's
website, transferred...
High
Unreviewed
CVE-2025-53520
was published
Aug 8, 2025
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This...
Moderate
Unreviewed
CVE-2025-8732
was published
Aug 8, 2025
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to...
Critical
Unreviewed
CVE-2025-8356
was published
Aug 8, 2025
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP...
Moderate
Unreviewed
CVE-2025-50927
was published
Aug 8, 2025
By default, the Packet Power Monitoring and Control Web Interface do not
enforce authentication...
Critical
Unreviewed
CVE-2025-8284
was published
Aug 8, 2025
ProTip!
Advisories are also available from the
GraphQL API