GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,489
Maven
5,000+
npm
5,000+
NuGet
892
pip
4,745
Pub
13
RubyGems
1,033
Rust
1,228
Swift
53
Unreviewed advisories
All unreviewed
5,000+
22 advisories
Filter by severity
Improper Control of Interaction Frequency in Apache syncope-core
Moderate
CVE-2018-17184
was published
for
org.apache.syncope:syncope-core
(Maven)
Nov 6, 2018
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior....
Moderate
Unreviewed
CVE-2023-2758
was published
May 31, 2023
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to...
Moderate
Unreviewed
CVE-2023-27279
was published
Apr 19, 2024
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding...
Moderate
Unreviewed
CVE-2024-24873
was published
May 17, 2024
: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha...
Moderate
Unreviewed
CVE-2023-40673
was published
Jun 4, 2024
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows...
Moderate
Unreviewed
CVE-2023-51544
was published
Jun 4, 2024
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an...
Moderate
Unreviewed
CVE-2024-0094
was published
Jun 14, 2024
Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large...
Moderate
Unreviewed
CVE-2024-9199
was published
Sep 26, 2024
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows...
Moderate
Unreviewed
CVE-2024-48942
was published
Oct 10, 2024
Drupal Open Social allows Functionality Misuse
Moderate
CVE-2024-13274
was published
for
goalgorilla/open_social
(Composer)
Jan 9, 2025
Missing rate limit in MaysWind ezBookkeeping
Moderate
CVE-2024-57603
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP...
Moderate
Unreviewed
CVE-2025-26524
was published
Feb 14, 2025
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings...
Moderate
Unreviewed
CVE-2023-40332
was published
Jun 4, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An...
Moderate
Unreviewed
CVE-2021-37191
was published
May 24, 2022
OpenFlow discovery protocol can exhaust resources because it is not rate limited
Moderate
Unreviewed
CVE-2025-48016
was published
May 20, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial...
Moderate
Unreviewed
CVE-2025-13211
was published
Dec 11, 2025
OpenClaw's hooks count non-POST requests toward auth lockout
Moderate
GHSA-6rmx-gvvg-vh6j
was published
for
openclaw
(npm)
Mar 9, 2026
Parse Server has a rate limit bypass via batch request endpoint
Moderate
CVE-2026-30972
was published
for
parse-server
(npm)
Mar 11, 2026
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated...
Moderate
Unreviewed
CVE-2026-22216
was published
Mar 13, 2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of...
Moderate
Unreviewed
CVE-2025-13212
was published
Mar 16, 2026
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive...
Moderate
Unreviewed
CVE-2025-55268
was published
Mar 26, 2026
ProTip!
Advisories are also available from the
GraphQL API