GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,246 advisories
Filter by severity
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-27883
was published
Jul 30, 2024
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The...
Moderate
Unreviewed
CVE-2025-21551
was published
Jan 21, 2025
Permission control vulnerability in the clock module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2023-52388
was published
Apr 8, 2024
From the VSPC management agent machine, under condition that the management agent is authorized...
High
Unreviewed
CVE-2024-42449
was published
Dec 4, 2024
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local...
Moderate
Unreviewed
CVE-2023-49582
was published
Aug 26, 2024
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone...
Moderate
Unreviewed
CVE-2024-0019
was published
Feb 16, 2024
Below has Incorrect Permission Assignment for Critical Resource
High
CVE-2025-27591
was published
for
below
(Rust)
Mar 11, 2025
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a...
High
Unreviewed
CVE-2025-22454
was published
Mar 11, 2025
Windows Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-36934
was published
May 24, 2022
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06...
High
Unreviewed
CVE-2022-45552
was published
Mar 3, 2023
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a...
High
Unreviewed
CVE-2025-1067
was published
Feb 25, 2025
@tanstack/form-core prototype pollution
High
CVE-2024-57068
was published
for
@tanstack/form-core
(npm)
Feb 6, 2025
Active Support Possibly Discloses Locally Encrypted Files
Moderate
CVE-2023-38037
was published
for
activesupport
(RubyGems)
Aug 23, 2023
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but...
Moderate
Unreviewed
CVE-2023-0225
was published
Apr 4, 2023
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update...
Moderate
Unreviewed
CVE-2023-0944
was published
Apr 5, 2023
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms...
High
Unreviewed
CVE-2023-24626
was published
Apr 8, 2023
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local...
High
Unreviewed
CVE-2024-13813
was published
Feb 11, 2025
A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC...
High
Unreviewed
CVE-2025-23403
was published
Feb 11, 2025
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business...
High
Unreviewed
CVE-2025-0064
was published
Feb 11, 2025
When etcupdate encounters conflicts while merging files, it saves a version containing conflict...
Moderate
Unreviewed
CVE-2025-0374
was published
Jan 30, 2025
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-57520
was published
Feb 6, 2025
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an...
High
Unreviewed
CVE-2025-24527
was published
Jan 29, 2025
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow...
Moderate
Unreviewed
CVE-2024-36294
was published
Nov 13, 2024
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local...
Moderate
Unreviewed
CVE-2024-45657
was published
Feb 4, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-21571
was published
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API