GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,388 advisories
Filter by severity
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
Below has Incorrect Permission Assignment for Critical Resource
High
CVE-2025-27591
was published
for
below
(Rust)
Mar 11, 2025
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
High
Unreviewed
CVE-2024-34897
was published
Feb 3, 2025
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password...
High
Unreviewed
CVE-2022-44216
was published
Feb 20, 2023
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged...
High
Unreviewed
CVE-2025-27688
was published
Mar 18, 2025
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
Critical
Unreviewed
CVE-2024-55959
was published
Jan 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The...
Moderate
Unreviewed
CVE-2025-21551
was published
Jan 21, 2025
Permission control vulnerability in the clock module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2023-52388
was published
Apr 8, 2024
From the VSPC management agent machine, under condition that the management agent is authorized...
High
Unreviewed
CVE-2024-42449
was published
Dec 4, 2024
Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local...
Moderate
Unreviewed
CVE-2023-49582
was published
Aug 26, 2024
In setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone...
Moderate
Unreviewed
CVE-2024-0019
was published
Feb 16, 2024
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a...
High
Unreviewed
CVE-2025-22454
was published
Mar 11, 2025
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06...
High
Unreviewed
CVE-2022-45552
was published
Mar 3, 2023
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a...
High
Unreviewed
CVE-2025-1067
was published
Feb 25, 2025
@tanstack/form-core prototype pollution
High
CVE-2024-57068
was published
for
@tanstack/form-core
(npm)
Feb 6, 2025
Active Support Possibly Discloses Locally Encrypted Files
Moderate
CVE-2023-38037
was published
for
activesupport
(RubyGems)
Aug 23, 2023
A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but...
Moderate
Unreviewed
CVE-2023-0225
was published
Apr 4, 2023
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update...
Moderate
Unreviewed
CVE-2023-0944
was published
Apr 5, 2023
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local...
High
Unreviewed
CVE-2024-13813
was published
Feb 11, 2025
A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC...
High
Unreviewed
CVE-2025-23403
was published
Feb 11, 2025
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business...
High
Unreviewed
CVE-2025-0064
was published
Feb 11, 2025
When etcupdate encounters conflicts while merging files, it saves a version containing conflict...
Moderate
Unreviewed
CVE-2025-0374
was published
Jan 30, 2025
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an...
High
Unreviewed
CVE-2025-24527
was published
Jan 29, 2025
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow...
Moderate
Unreviewed
CVE-2024-36294
was published
Nov 13, 2024
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local...
Moderate
Unreviewed
CVE-2024-45657
was published
Feb 4, 2025
ProTip!
Advisories are also available from the
GraphQL API