GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
25 advisories
Filter by severity
PocketMine-MP: JSON decoding of unlimited size large arrays/objects in ModalFormResponse Handling
High
GHSA-788v-5pfp-93ff
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service
Moderate
CVE-2026-33541
was published
for
miraheze/ts-portal
(Composer)
Mar 27, 2026
ConcreteCMS is vulnerable to Denial of Service During Bulk Downloads
Moderate
CVE-2026-30662
was published
for
concrete5/concrete5
(Composer)
Mar 24, 2026
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
High
CVE-2026-33483
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
Moderate
CVE-2026-26047
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
solspace/craft-freeform Has a DoS Vulnerability
Low
GHSA-58q2-9x27-h2jm
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
Unauthenticated Craft CMS users can trigger a database backup
High
CVE-2025-68456
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
PocketMine-MP `ResourcePackDataInfoPacket` amplification vulnerability due to lack of resource pack sequence status checking
High
GHSA-fqqv-56h5-f57g
was published
for
pocketmine/pocketmine-mp
(Composer)
Sep 2, 2025
FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of Service
Moderate
CVE-2025-54869
was published
for
setasign/fpdi
(Composer)
Aug 5, 2025
Drupal Admin Audit Trail Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-48448
was published
for
drupal/admin_audit_trail
(Composer)
Jun 11, 2025
PocketMine-MP allows malicious client data to waste server resources due to lack of limits for explode()
Moderate
GHSA-g274-c6jj-h78p
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 10, 2025
TYPO3 Denial of Service in Online Media Asset Handling
Moderate
GHSA-f3wf-q4fj-3gxf
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Denial of Service in Frontend Record Registration
High
GHSA-g585-crjf-vhwq
was published
for
typo3/cms
(Composer)
Jun 7, 2024
Flooding Server with Thumbnail files
High
CVE-2024-32871
was published
for
pimcore/pimcore
(Composer)
Jun 4, 2024
TYPO3 Denial of Service in Frontend Record Registration
High
GHSA-hjx5-v9xg-7h25
was published
for
typo3/cms-core
(Composer)
May 30, 2024
TYPO3 Denial of Service in Online Media Asset Handling
Moderate
GHSA-29m4-mx89-3mjg
was published
for
typo3/cms-core
(Composer)
May 30, 2024
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
LibreNMS vulnerable to rate limiting bypass on login page
Moderate
CVE-2023-46745
was published
for
librenms/librenms
(Composer)
Nov 17, 2023
Denial of service from unlimited password lengths
Moderate
CVE-2023-38492
was published
for
getkirby/cms
(Composer)
Jul 28, 2023
Wallabag vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2023-3566
was published
for
wallabag/wallabag
(Composer)
Jul 10, 2023
Concrete CMS vulnerable to Uncontrolled Resource Consumption leading to DoS
Moderate
CVE-2022-43686
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling
Moderate
CVE-2022-36104
was published
for
typo3/cms
(Composer)
Sep 16, 2022
Moodle Client side denial of service via personal message
Moderate
CVE-2021-20185
was published
for
moodle/moodle
(Composer)
May 24, 2022
Moodle denial-of-service risk in the draft files area
High
CVE-2021-32476
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
ProTip!
Advisories are also available from the
GraphQL API