GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
225 advisories
Filter by severity
A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation...
Moderate
Unreviewed
CVE-2025-62876
was published
Nov 12, 2025
The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator...
Moderate
Unreviewed
CVE-2025-9055
was published
Nov 11, 2025
Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with...
High
Unreviewed
CVE-2025-46430
was published
Nov 10, 2025
IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under...
High
Unreviewed
CVE-2025-36186
was published
Nov 7, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary...
Critical
Unreviewed
CVE-2025-34515
was published
Oct 16, 2025
Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges...
Critical
Unreviewed
CVE-2025-34274
was published
Oct 31, 2025
A maliciously crafted file, when executed on the victim's machine, can lead to privilege...
High
Unreviewed
CVE-2025-10885
was published
Nov 6, 2025
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly...
High
Unreviewed
CVE-2021-47700
was published
Oct 31, 2025
Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG...
High
Unreviewed
CVE-2018-25123
was published
Oct 31, 2025
Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary...
High
Unreviewed
CVE-2025-43990
was published
Nov 5, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS...
High
Unreviewed
CVE-2024-23299
was published
Jun 10, 2024
The www-data user can elevate its privileges because sudo is configured to allow the execution of...
High
Unreviewed
CVE-2024-28139
was published
Dec 11, 2024
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate...
High
Unreviewed
CVE-2024-35141
was published
Dec 19, 2024
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a...
Moderate
Unreviewed
CVE-2024-28140
was published
Dec 11, 2024
Attackers with local access to the medical office computer can
escalate their Windows user...
High
Unreviewed
CVE-2024-50590
was published
Nov 8, 2024
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain...
High
Unreviewed
CVE-2023-30998
was published
Jun 27, 2024
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate...
High
Unreviewed
CVE-2024-35142
was published
May 31, 2024
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain...
High
Unreviewed
CVE-2023-30997
was published
Jun 27, 2024
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges....
Low
Unreviewed
CVE-2019-15790
was published
May 24, 2022
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain...
High
Unreviewed
CVE-2025-33003
was published
Oct 31, 2025
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2...
High
Unreviewed
CVE-2025-36137
was published
Oct 30, 2025
Apache Airflow's create action can upsert existing Pools/Connections/Variables
Moderate
CVE-2025-62503
was published
for
apache-airflow
(pip)
Oct 30, 2025
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Moderate
CVE-2025-62402
was published
for
apache-airflow
(pip)
Oct 30, 2025
The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network...
High
Unreviewed
CVE-2024-38813
was published
Sep 17, 2024
An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network...
Critical
Unreviewed
CVE-2025-6949
was published
Oct 17, 2025
ProTip!
Advisories are also available from the
GraphQL API