GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
225 advisories
Filter by severity
A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows...
High
Unreviewed
CVE-2022-43553
was published
Dec 6, 2022
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local...
High
Unreviewed
CVE-2025-1951
was published
Apr 22, 2025
Harden-Runner allows evasion of 'disable-sudo' policy
Moderate
CVE-2025-32955
was published
for
step-security/harden-runner
(GitHub Actions)
Apr 22, 2025
A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit)...
Moderate
Unreviewed
CVE-2025-23009
was published
Apr 10, 2025
An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64...
High
Unreviewed
CVE-2025-23008
was published
Apr 10, 2025
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers...
Critical
Unreviewed
CVE-2025-3364
was published
Apr 8, 2025
Tomcat uses trusted privileges when processing web.xml file
Moderate
CVE-2003-0043
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 29, 2022
man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain...
High
Unreviewed
CVE-2018-25078
was published
Jan 26, 2023
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21003
was published
Apr 17, 2024
A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability...
Moderate
Unreviewed
CVE-2024-11821
was published
Mar 20, 2025
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an...
High
Unreviewed
CVE-2024-48013
was published
Mar 17, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Zones). The supported...
High
Unreviewed
CVE-2024-20999
was published
Apr 17, 2024
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst....
High
Unreviewed
CVE-2023-27010
was published
Mar 13, 2023
Winlogon Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-43583
was published
Oct 8, 2024
Apache Solr vulnerable to Execution with Unnecessary Privileges
High
CVE-2025-24814
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be...
High
Unreviewed
CVE-2023-0664
was published
Mar 29, 2023
An issue in Cynet Client Agent v4.6.0.8010 allows attackers with Administrator rights to disable...
Moderate
Unreviewed
CVE-2023-27247
was published
Mar 28, 2023
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0...
Moderate
Unreviewed
CVE-2024-8266
was published
Feb 13, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0...
Critical
Unreviewed
CVE-2024-7102
was published
Feb 13, 2025
An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo...
High
Unreviewed
CVE-2024-12673
was published
Feb 12, 2025
SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to...
High
Unreviewed
CVE-2024-21924
was published
Feb 11, 2025
Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x...
Moderate
Unreviewed
CVE-2025-22890
was published
Feb 6, 2025
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated...
High
Unreviewed
CVE-2024-49814
was published
Feb 6, 2025
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS...
Low
Unreviewed
CVE-2025-20185
was published
Feb 5, 2025
ProTip!
Advisories are also available from the
GraphQL API