GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
306 advisories
Filter by severity
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server...
Moderate
Unreviewed
CVE-2024-52869
was published
Jan 8, 2025
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and...
High
Unreviewed
CVE-2022-26024
was published
Nov 11, 2022
RuoYi vulnerable to Denial of Service by attackers with admin privileges
Moderate
CVE-2024-57439
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
snowflake-sdk may incorrectly validate temporary credential cache file permissions
Moderate
CVE-2025-24791
was published
for
snowflake-sdk
(npm)
Jan 29, 2025
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki
High
CVE-2021-3978
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 19, 2021
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the...
Moderate
Unreviewed
CVE-2024-56178
was published
Jan 28, 2025
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections...
High
Unreviewed
CVE-2024-40672
was published
Jan 28, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42231
was published
Jan 14, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42228
was published
Jan 14, 2025
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens...
Moderate
Unreviewed
CVE-2025-21541
was published
Jan 21, 2025
Vulnerability in the Oracle Communications Order and Service Management product of Oracle...
Moderate
Unreviewed
CVE-2025-21544
was published
Jan 21, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
Insecure default config access in WriteFreely
High
CVE-2025-24337
was published
for
github.com/writefreely/writefreely
(Go)
Jan 20, 2025
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to...
Critical
Unreviewed
CVE-2024-46310
was published
Jan 13, 2025
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access...
High
Unreviewed
CVE-2024-54818
was published
Jan 8, 2025
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes)...
High
Unreviewed
CVE-2024-53934
was published
Jan 7, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54880
was published
Jan 6, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54879
was published
Jan 6, 2025
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software...
Critical
Unreviewed
CVE-2024-46622
was published
Jan 6, 2025
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2024-55507
was published
Jan 3, 2025
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes...
High
Unreviewed
CVE-2024-56317
was published
Dec 19, 2024
Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before...
Moderate
Unreviewed
CVE-2024-37649
was published
Dec 19, 2024
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers...
Moderate
Unreviewed
CVE-2024-50921
was published
Dec 10, 2024
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
High
Unreviewed
CVE-2024-50930
was published
Dec 10, 2024
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers...
Moderate
Unreviewed
CVE-2024-50924
was published
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API