GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,732
Erlang
35
GitHub Actions
29
Go
2,310
Maven
5,000+
npm
3,949
NuGet
711
pip
3,728
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
632 advisories
Filter by severity
In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from...
High
Unreviewed
CVE-2024-0034
was published
Feb 16, 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2024-21116
was published
Apr 17, 2024
Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
High
CVE-2025-24399
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 22, 2025
Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies....
High
Unreviewed
CVE-2025-22918
was published
Feb 3, 2025
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to...
High
Unreviewed
CVE-2024-49744
was published
Jan 22, 2025
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). ...
High
Unreviewed
CVE-2025-21532
was published
Jan 21, 2025
Privilege escalation in Automatic Systems Maintenance SlimLane...
High
Unreviewed
CVE-2024-48822
was published
Oct 14, 2024
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been...
High
Unreviewed
CVE-2024-39924
was published
Sep 13, 2024
In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to...
High
Unreviewed
CVE-2024-40655
was published
Sep 11, 2024
Permission control vulnerability in the calendarProvider module.Successful exploitation of this...
High
Unreviewed
CVE-2023-52379
was published
Feb 18, 2024
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking...
High
Unreviewed
CVE-2024-43765
was published
Jan 22, 2025
In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control...
High
Unreviewed
CVE-2024-55957
was published
Jan 22, 2025
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant...
High
Unreviewed
CVE-2024-49732
was published
Jan 22, 2025
An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local...
High
Unreviewed
CVE-2024-30977
was published
Apr 5, 2024
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an...
High
Unreviewed
CVE-2024-49742
was published
Jan 22, 2025
Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address...
High
Unreviewed
CVE-2024-44786
was published
Nov 22, 2024
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06...
High
Unreviewed
CVE-2022-45552
was published
Mar 3, 2023
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows)...
High
Unreviewed
CVE-2025-22447
was published
Mar 6, 2025
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows)...
High
Unreviewed
CVE-2025-24864
was published
Mar 6, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate...
High
Unreviewed
CVE-2023-27091
was published
Apr 4, 2023
When the installation directory does not have sufficiently restrictive file permissions, an...
High
Unreviewed
CVE-2022-43701
was published
Jul 28, 2023
When the directory containing the installer does not have sufficiently restrictive file...
High
Unreviewed
CVE-2022-43702
was published
Jul 28, 2023
NGINX Management Suite default file permissions are set such that an authenticated attacker may...
High
Unreviewed
CVE-2023-28724
was published
Jul 6, 2023
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local...
High
Unreviewed
CVE-2024-1156
was published
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API