GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,676
Erlang
34
GitHub Actions
26
Go
2,263
Maven
5,000+
npm
3,915
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
Memory write permission bypass vulnerability in the kernel futex module
Impact: Successful...
High
Unreviewed
CVE-2025-31173
was published
Apr 7, 2025
Memory write permission bypass vulnerability in the kernel futex module
Impact: Successful...
High
Unreviewed
CVE-2025-31172
was published
Apr 7, 2025
Software installed and run as a non-privileged user may conduct improper GPU system calls to...
High
Unreviewed
CVE-2025-0468
was published
Apr 4, 2025
An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B...
Moderate
Unreviewed
CVE-2024-8315
was published
Mar 25, 2025
Software installed and run as a non-privileged user may conduct improper GPU system calls to...
High
Unreviewed
CVE-2025-0478
was published
Mar 24, 2025
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands...
High
Unreviewed
CVE-2024-51459
was published
Mar 19, 2025
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission...
Moderate
Unreviewed
CVE-2025-20649
was published
Mar 3, 2025
The product does not handle or incorrectly handles when it has insufficient privileges to access...
Moderate
Unreviewed
CVE-2024-6697
was published
Feb 20, 2025
An attacker who successfully exploited these vulnerabilities could cause enable command execution...
High
Unreviewed
CVE-2024-12430
was published
Jan 7, 2025
Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege...
High
Unreviewed
CVE-2025-22395
was published
Jan 7, 2025
Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to...
High
Unreviewed
CVE-2024-43705
was published
Dec 28, 2024
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An...
Low
Unreviewed
CVE-2024-42194
was published
Dec 17, 2024
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients...
Critical
Unreviewed
CVE-2024-46874
was published
Dec 6, 2024
Software installed and run as a non-privileged user may conduct improper GPU system calls to...
High
Unreviewed
CVE-2024-43702
was published
Nov 30, 2024
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass...
Moderate
Unreviewed
CVE-2023-39249
was published
Oct 17, 2024
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4211
was published
Oct 16, 2024
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4692
was published
Oct 16, 2024
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain...
Critical
Unreviewed
CVE-2024-24116
was published
Oct 2, 2024
Certain switch models from PLANET Technology have an SSH service that improperly handles...
High
Unreviewed
CVE-2024-8451
was published
Sep 30, 2024
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and...
Critical
Unreviewed
CVE-2024-7314
was published
Aug 2, 2024
Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm...
High
Unreviewed
CVE-2024-36451
was published
Jul 10, 2024
Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access to
Moderate
CVE-2024-39691
was published
for
matrix-appservice-irc
(npm)
Jul 5, 2024
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower,...
High
Unreviewed
CVE-2024-6302
was published
Jun 25, 2024
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user...
Critical
Unreviewed
CVE-2024-5163
was published
Jun 17, 2024
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
Moderate
CVE-2024-35228
was published
for
wagtail
(pip)
Jun 2, 2024
ProTip!
Advisories are also available from the
GraphQL API