GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,838
Erlang
36
GitHub Actions
33
Go
2,460
Maven
5,000+
npm
4,082
NuGet
723
pip
3,872
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
510 advisories
Filter by severity
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow...
Moderate
Unreviewed
CVE-2025-2503
was published
May 30, 2025
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an...
Moderate
Unreviewed
CVE-2024-11176
was published
Nov 20, 2024
Permission control vulnerability in the distributed clipboard module.
Impact: Successful...
Moderate
Unreviewed
CVE-2025-54618
was published
Aug 6, 2025
IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they...
Moderate
Unreviewed
CVE-2025-1139
was published
Aug 20, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 17.11.6, 18...
Moderate
Unreviewed
CVE-2025-5819
was published
Aug 13, 2025
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest...
Moderate
Unreviewed
CVE-2025-23285
was published
Aug 3, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43266
was published
Jul 30, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43247
was published
Jul 30, 2025
IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive...
Moderate
Unreviewed
CVE-2025-36104
was published
Jul 12, 2025
Enables an authenticated user (enrolled device) to access a service protected by Sentry even if...
Moderate
Unreviewed
CVE-2023-39338
was published
Jul 12, 2025
Canon EOS Webcam Utility Pro for MAC OS version 2.3d
(2.3.29) and earlier contains an improper...
Moderate
Unreviewed
CVE-2025-5995
was published
Jun 26, 2025
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with...
Moderate
Unreviewed
CVE-2024-11584
was published
Jun 26, 2025
Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.
Moderate
Unreviewed
CVE-2025-52923
was published
Jun 22, 2025
A vulnerability was found in logrotate in how the state file is created. The state file is used...
Moderate
Unreviewed
CVE-2022-1348
was published
May 26, 2022
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-23223
was published
Jan 23, 2024
IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform...
Moderate
Unreviewed
CVE-2024-45655
was published
Jun 3, 2025
An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element...
Moderate
Unreviewed
CVE-2020-15595
was published
May 24, 2022
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v...
Moderate
Unreviewed
CVE-2025-48747
was published
May 28, 2025
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the...
Moderate
Unreviewed
CVE-2025-46802
was published
May 26, 2025
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect...
Moderate
Unreviewed
CVE-2025-32915
was published
May 22, 2025
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework...
Moderate
Unreviewed
CVE-2025-3936
was published
May 22, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2...
Moderate
Unreviewed
CVE-2025-31262
was published
May 19, 2025
Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before...
Moderate
Unreviewed
CVE-2022-3325
was published
Oct 17, 2022
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions)....
Moderate
Unreviewed
CVE-2025-40572
was published
May 13, 2025
Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted...
Moderate
Unreviewed
CVE-2025-42997
was published
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API