GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,838
Erlang
36
GitHub Actions
33
Go
2,460
Maven
5,000+
npm
4,082
NuGet
723
pip
3,872
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,338 advisories
Filter by severity
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect...
Moderate
Unreviewed
CVE-2025-32915
was published
May 22, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework...
High
Unreviewed
CVE-2025-3944
was published
May 22, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework...
Moderate
Unreviewed
CVE-2025-3936
was published
May 22, 2025
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2025-2759
was published
May 22, 2025
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and...
High
Unreviewed
CVE-2025-34025
was published
May 22, 2025
If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15...
High
Unreviewed
CVE-2022-40756
was published
Oct 1, 2022
A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2...
Moderate
Unreviewed
CVE-2025-31262
was published
May 19, 2025
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before...
Moderate
Unreviewed
CVE-2022-3325
was published
Oct 17, 2022
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions)....
Moderate
Unreviewed
CVE-2025-40572
was published
May 13, 2025
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions)....
High
Unreviewed
CVE-2025-40574
was published
May 13, 2025
A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions),...
High
Unreviewed
CVE-2025-24009
was published
May 13, 2025
Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted...
Moderate
Unreviewed
CVE-2025-42997
was published
May 13, 2025
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms...
High
Unreviewed
CVE-2023-24626
was published
Apr 8, 2023
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there...
High
Unreviewed
CVE-2025-26169
was published
May 7, 2025
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because...
High
Unreviewed
CVE-2025-26168
was published
May 7, 2025
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux)...
High
Unreviewed
CVE-2024-13861
was published
Apr 11, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1...
Moderate
Unreviewed
CVE-2022-32929
was published
Nov 2, 2022
A permissions issue existed. This issue was addressed with improved permission validation. This...
Moderate
Unreviewed
CVE-2022-42788
was published
Nov 2, 2022
A vulnerability has been identified in Node.js version 20, affecting users of the experimental...
Moderate
Unreviewed
CVE-2023-32005
was published
Sep 20, 2023
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager ...
Moderate
Unreviewed
CVE-2025-23245
was published
May 1, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder...
High
Unreviewed
CVE-2025-3394
was published
Apr 30, 2025
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of...
High
Unreviewed
CVE-2022-45193
was published
Nov 12, 2022
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a...
High
Unreviewed
CVE-2022-44725
was published
Nov 18, 2022
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master...
Moderate
Unreviewed
CVE-2022-44280
was published
Nov 23, 2022
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to...
Moderate
Unreviewed
CVE-2022-46338
was published
Nov 30, 2022
ProTip!
Advisories are also available from the
GraphQL API