GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,026
Maven
5,000+
npm
4,763
NuGet
824
pip
4,366
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
49 advisories
Filter by severity
Keycloak Affected by Broken Access Control Vulnerability in the UserManagedPermissionService
Moderate
CVE-2025-14778
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 9, 2026
Keycloak Admin API allows an administrator with limited privileges to retrieve sensitive custom attributes
Low
CVE-2025-13881
was published
for
org.keycloak:keycloak-services
(Maven)
Feb 2, 2026
MineAdmin has Incorrect Privilege Assignment
Low
CVE-2026-1193
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
Critical
CVE-2025-13888
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Dec 15, 2025
sd changes the group ownership of the source file
Moderate
CVE-2025-65807
was published
for
sd
(Rust)
Dec 10, 2025
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
High
CVE-2025-66296
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
NutzBoot Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-13806
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
Grafana Incorrect Privilege Assignment vulnerability
Critical
CVE-2025-41115
was published
for
github.com/grafana/grafana
(Go)
Nov 21, 2025
Observability Operator is vulnerable to Incorrect Privilege Assignment through its Custom Resource MonitorStack
High
CVE-2025-2843
was published
for
github.com/rhobs/observability-operator
(Go)
Nov 12, 2025
Deno's --deny-write check does not prevent permission bypass
Low
CVE-2025-61785
was published
for
deno
(Rust)
Oct 7, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High
CVE-2025-54996
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High
CVE-2025-5999
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing Import Page component
Low
CVE-2025-6735
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing certain components
Low
CVE-2025-6736
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
New authd users logging in via SSH are members of the root group
Moderate
CVE-2025-5689
was published
for
github.com/ubuntu/authd
(Go)
Jun 16, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High
CVE-2025-4922
was published
for
github.com/hashicorp/nomad
(Go)
Jun 11, 2025
Duplicate Advisory: users may append `root` to group listings
High
GHSA-jq8x-v7jw-v675
was published
for
users
(Rust)
Jun 6, 2025
•
withdrawn
users may append `root` to group listings
High
CVE-2025-5791
was published
for
users
(Rust)
Jun 5, 2025
pypickle Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-5175
was published
for
pypickle
(pip)
May 26, 2025
containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.
Moderate
CVE-2025-47291
was published
for
github.com/containerd/containerd/v2
(Go)
May 21, 2025
Rancher: Restricted Administrator can change Administrator's passwords
Critical
CVE-2025-23391
was published
for
github.com/rancher/rancher
(Go)
Apr 1, 2025
LiteLLM Has an Improper Authorization Vulnerability
High
CVE-2025-0628
was published
for
litellm
(pip)
Mar 20, 2025
Karmada PULL Mode Cluster Privilege Escalation
High
CVE-2024-56513
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
ProTip!
Advisories are also available from the
GraphQL API