GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,838
Erlang
36
GitHub Actions
33
Go
2,460
Maven
5,000+
npm
4,082
NuGet
723
pip
3,873
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,338 advisories
Filter by severity
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2...
Moderate
Unreviewed
CVE-2024-38864
was published
Dec 19, 2024
A flaw was found in the OpenShift build process, where the docker-build container is configured...
High
Unreviewed
CVE-2024-45497
was published
Dec 31, 2024
Sensitive information disclosure due to insecure folder permissions. The following products are...
Moderate
Unreviewed
CVE-2024-49385
was published
Jan 2, 2025
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for...
Moderate
Unreviewed
CVE-2024-47475
was published
Jan 6, 2025
The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme)...
Critical
Unreviewed
CVE-2024-53932
was published
Jan 7, 2025
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for...
Critical
Unreviewed
CVE-2024-53931
was published
Jan 7, 2025
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to...
High
Unreviewed
CVE-2024-55411
was published
Jan 7, 2025
Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File...
Moderate
Unreviewed
CVE-2024-54910
was published
Jan 10, 2025
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication...
Critical
Unreviewed
CVE-2025-0066
was published
Jan 14, 2025
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain...
High
Unreviewed
CVE-2024-11497
was published
Jan 14, 2025
Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information...
Moderate
Unreviewed
CVE-2024-39967
was published
Jan 16, 2025
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21325
was published
Jan 17, 2025
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a...
Moderate
Unreviewed
CVE-2024-51448
was published
Jan 18, 2025
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an...
Critical
Unreviewed
CVE-2024-38337
was published
Jan 19, 2025
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to
...
High
Unreviewed
CVE-2025-0590
was published
Jan 20, 2025
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
Critical
Unreviewed
CVE-2024-55959
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-21523
was published
Jan 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The...
Moderate
Unreviewed
CVE-2025-21551
was published
Jan 21, 2025
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile...
High
Unreviewed
CVE-2025-21564
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-21566
was published
Jan 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-21571
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Low
Unreviewed
CVE-2025-21520
was published
Jan 21, 2025
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the...
Low
Unreviewed
CVE-2024-52328
was published
Jan 23, 2025
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project...
High
Unreviewed
CVE-2024-46881
was published
Jan 26, 2025
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-57547
was published
Jan 28, 2025
ProTip!
Advisories are also available from the
GraphQL API