GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,838
Erlang
36
GitHub Actions
33
Go
2,460
Maven
5,000+
npm
4,082
NuGet
723
pip
3,873
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,338 advisories
Filter by severity
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary...
High
Unreviewed
CVE-2017-8665
was published
May 13, 2022
It was found that rhnsd PID files are created as world-writable that allows local attackers to...
Moderate
Unreviewed
CVE-2017-7560
was published
May 13, 2022
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software...
High
Unreviewed
CVE-2017-9958
was published
May 13, 2022
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an...
Moderate
Unreviewed
CVE-2017-9792
was published
May 13, 2022
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write...
Moderate
Unreviewed
CVE-2017-15906
was published
May 13, 2022
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to...
High
Unreviewed
CVE-2017-5260
was published
May 13, 2022
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5)...
High
Unreviewed
CVE-2017-16895
was published
May 13, 2022
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions:...
High
Unreviewed
CVE-2017-13168
was published
May 13, 2022
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET...
High
Unreviewed
CVE-2022-30354
was published
Oct 25, 2024
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible...
Moderate
Unreviewed
CVE-2025-0926
was published
Apr 23, 2025
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for...
High
Unreviewed
CVE-2022-46792
was published
Dec 8, 2022
An incorrect permission assignment vulnerability in the PostgreSQL commands of the USG FLEX H...
High
Unreviewed
CVE-2025-1731
was published
Apr 22, 2025
Local privilege escalation due to insecure folder permissions. The following products are...
Moderate
Unreviewed
CVE-2025-30408
was published
Apr 24, 2025
g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to...
Moderate
Unreviewed
CVE-2022-46338
was published
Nov 30, 2022
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master...
Moderate
Unreviewed
CVE-2022-44280
was published
Nov 23, 2022
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of...
High
Unreviewed
CVE-2022-45193
was published
Nov 12, 2022
OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a...
High
Unreviewed
CVE-2022-44725
was published
Nov 18, 2022
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder...
High
Unreviewed
CVE-2025-3394
was published
Apr 30, 2025
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager ...
Moderate
Unreviewed
CVE-2025-23245
was published
May 1, 2025
A vulnerability has been identified in Node.js version 20, affecting users of the experimental...
Moderate
Unreviewed
CVE-2023-32005
was published
Sep 20, 2023
A permissions issue existed. This issue was addressed with improved permission validation. This...
Moderate
Unreviewed
CVE-2022-42788
was published
Nov 2, 2022
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1...
Moderate
Unreviewed
CVE-2022-32929
was published
Nov 2, 2022
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux)...
High
Unreviewed
CVE-2024-13861
was published
Apr 11, 2025
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there...
High
Unreviewed
CVE-2025-26169
was published
May 7, 2025
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because...
High
Unreviewed
CVE-2025-26168
was published
May 7, 2025
ProTip!
Advisories are also available from the
GraphQL API