GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,259
NuGet
760
pip
4,052
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
525 advisories
Filter by severity
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported...
Moderate
Unreviewed
CVE-2025-21580
was published
Apr 15, 2025
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow...
Moderate
Unreviewed
CVE-2025-25041
was published
Apr 1, 2025
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local...
Moderate
Unreviewed
CVE-2024-45657
was published
Feb 4, 2025
When etcupdate encounters conflicts while merging files, it saves a version containing conflict...
Moderate
Unreviewed
CVE-2025-0374
was published
Jan 30, 2025
Apache Hive Incorrectly Assigns Permissions for a Critical Resource
Moderate
CVE-2024-29869
was published
for
org.apache.hive:hive-exec
(Maven)
Jan 29, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-21566
was published
Jan 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The...
Moderate
Unreviewed
CVE-2025-21551
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-21523
was published
Jan 21, 2025
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a...
Moderate
Unreviewed
CVE-2024-51448
was published
Jan 18, 2025
Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information...
Moderate
Unreviewed
CVE-2024-39967
was published
Jan 16, 2025
Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File...
Moderate
Unreviewed
CVE-2024-54910
was published
Jan 10, 2025
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for...
Moderate
Unreviewed
CVE-2024-47475
was published
Jan 6, 2025
Sensitive information disclosure due to insecure folder permissions. The following products are...
Moderate
Unreviewed
CVE-2024-49385
was published
Jan 2, 2025
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents...
Moderate
Unreviewed
CVE-2024-55955
was published
Dec 31, 2024
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2...
Moderate
Unreviewed
CVE-2024-38864
was published
Dec 19, 2024
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical...
Moderate
Unreviewed
CVE-2024-47104
was published
Dec 18, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open...
Moderate
Unreviewed
CVE-2024-12564
was published
Dec 12, 2024
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information...
Moderate
Unreviewed
CVE-2024-12255
was published
Dec 12, 2024
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices...
Moderate
Unreviewed
CVE-2024-8256
was published
Dec 10, 2024
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.8...
Moderate
Unreviewed
CVE-2024-45841
was published
Dec 5, 2024
Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0...
Moderate
Unreviewed
CVE-2024-12151
was published
Dec 4, 2024
stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp...
Moderate
Unreviewed
CVE-2024-54159
was published
Nov 30, 2024
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of...
Moderate
Unreviewed
CVE-2024-21703
was published
Nov 27, 2024
Affected devices create coredump files when crashed, storing them with world-readable permission....
Moderate
Unreviewed
CVE-2024-28955
was published
Nov 26, 2024
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an...
Moderate
Unreviewed
CVE-2024-11176
was published
Nov 20, 2024
ProTip!
Advisories are also available from the
GraphQL API