GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
281 advisories
Filter by severity
Moderate severity vulnerability that affects org.apache.tika:tika-core
Moderate
CVE-2018-1338
was published
for
org.apache.tika:tika-core
(Maven)
Oct 17, 2018
Moderate severity vulnerability that affects io.undertow:undertow-core
Moderate
CVE-2017-2670
was published
for
io.undertow:undertow-core
(Maven)
Oct 19, 2018
Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate
CVE-2018-10912
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 18, 2018
Denial of Service in docker2aci
Moderate
CVE-2016-8579
was published
for
github.com/appc/docker2aci
(Go)
Feb 15, 2022
Junrar vulnerable to Infinite Loop
Moderate
CVE-2018-12418
was published
for
com.github.junrar:junrar
(Maven)
Oct 17, 2018
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer...
Moderate
Unreviewed
CVE-2022-24191
was published
Apr 5, 2022
Loop with Unreachable Exit Condition in Apache POI
Moderate
CVE-2014-9527
was published
for
org.apache.poi:poi
(Maven)
May 17, 2022
Loop with Unreachable Exit Condition in Apache PDFBox
Moderate
CVE-2018-8036
was published
for
org.apache.pdfbox:pdfbox
(Maven)
May 13, 2022
XStream can cause a Denial of Service
Moderate
CVE-2021-39140
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
Infinite Loop in Apache PDFBox
Moderate
CVE-2021-31812
was published
for
org.apache.pdfbox:pdfbox
(Maven)
Jun 15, 2021
A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the...
Moderate
Unreviewed
CVE-2022-4104
was published
Nov 28, 2022
long running loops in grant table handling In order to properly monitor resource use, Xen...
Moderate
Unreviewed
CVE-2021-28698
was published
May 24, 2022
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device...
Moderate
Unreviewed
CVE-2021-20255
was published
May 24, 2022
An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial...
Moderate
Unreviewed
CVE-2022-35165
was published
Aug 19, 2022
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG:...
Moderate
Unreviewed
CVE-2022-35166
was published
Aug 19, 2022
Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and...
Moderate
Unreviewed
CVE-2018-6687
was published
May 13, 2022
DoS vulnerability in MaliciousCode filter
Moderate
CVE-2023-23617
was published
for
openmage/magento-lts
(Composer)
Jan 27, 2023
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization...
Moderate
Unreviewed
CVE-2022-29028
was published
May 21, 2022
Infinite Loop in Apache Tika
Moderate
CVE-2020-1951
was published
for
org.apache.tika:tika
(Maven)
May 7, 2021
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to...
Moderate
Unreviewed
CVE-2013-7488
was published
May 5, 2022
Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an...
Moderate
Unreviewed
CVE-2019-13453
was published
May 24, 2022
An infinite loop may be triggered in display_debug_abbrev() function in binutils/dwarf.c while...
Moderate
Unreviewed
CVE-2022-38128
was published
Sep 2, 2022
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service...
Moderate
Unreviewed
CVE-2019-15143
was published
May 24, 2022
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid...
Moderate
Unreviewed
CVE-2019-19451
was published
May 24, 2022
An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality...
Moderate
Unreviewed
CVE-2019-5091
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API