GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,388 advisories
Filter by severity
A vulnerability has been identified in POWER METER SICAM Q200 family (All versions < V2.70)....
Moderate
Unreviewed
CVE-2023-31238
was published
Jun 13, 2023
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
Moderate
Unreviewed
CVE-2024-32014
was published
Nov 11, 2025
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
High
Unreviewed
CVE-2024-32010
was published
Nov 11, 2025
An ACAP configuration file has improper permissions and lacks input validation, which could...
Moderate
Unreviewed
CVE-2025-8108
was published
Nov 11, 2025
An ACAP configuration file has improper permissions, which could allow command injection and...
Moderate
Unreviewed
CVE-2025-6779
was published
Nov 11, 2025
The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to...
Moderate
Unreviewed
CVE-2025-43079
was published
Nov 10, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write
High
CVE-2025-64324
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 7, 2025
Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets...
Moderate
Unreviewed
CVE-2025-34135
was published
Oct 31, 2025
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which...
High
Unreviewed
CVE-2025-34287
was published
Oct 31, 2025
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-57520
was published
Feb 6, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft...
Moderate
Unreviewed
CVE-2025-64319
was published
Nov 4, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin...
High
Unreviewed
CVE-2025-27446
was published
Jul 6, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce...
Moderate
Unreviewed
CVE-2025-64322
was published
Nov 4, 2025
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-23223
was published
Jan 23, 2024
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS...
Moderate
Unreviewed
CVE-2023-42924
was published
Dec 12, 2023
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
Moderate
Unreviewed
CVE-2022-48257
was published
Jan 13, 2023
Affected devices create coredump files when crashed, storing them with world-readable permission....
Moderate
Unreviewed
CVE-2024-28955
was published
Nov 26, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-27883
was published
Jul 30, 2024
Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file
High
Unreviewed
CVE-2023-4332
was published
Aug 15, 2023
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID...
High
Unreviewed
CVE-2022-23132
was published
Jan 14, 2022
Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities...
High
Unreviewed
CVE-2023-32724
was published
Oct 12, 2023
iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY...
High
Unreviewed
CVE-2025-10541
was published
Sep 25, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43266
was published
Jul 30, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-43243
was published
Jul 30, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported...
Moderate
Unreviewed
CVE-2025-21580
was published
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API