GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,329
NuGet
762
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,861 advisories
Filter by severity
Input verification vulnerability in the compression and decompression module. Impact: Successful...
High
Unreviewed
CVE-2025-66324
was published
Dec 8, 2025
A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to...
High
Unreviewed
CVE-2025-13292
was published
Dec 6, 2025
A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper...
Moderate
Unreviewed
CVE-2025-62686
was published
Dec 3, 2025
A local privilege escalation vulnerability exists in the InstallationHelper service included with...
Moderate
Unreviewed
CVE-2025-55076
was published
Dec 3, 2025
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An...
High
Unreviewed
CVE-2025-7044
was published
Dec 3, 2025
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions...
Critical
Unreviewed
CVE-2025-13542
was published
Dec 2, 2025
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
High
Unreviewed
CVE-2025-59697
was published
Dec 2, 2025
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through...
Critical
Unreviewed
CVE-2025-59693
was published
Dec 2, 2025
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-13534
was published
Dec 2, 2025
Snipe-IT is vulnerable to stored cross-site scripting
Moderate
CVE-2025-65621
was published
for
snipe/snipe-it
(Composer)
Dec 1, 2025
Improper Privilege Management vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks...
Moderate
Unreviewed
CVE-2025-59790
was published
Nov 28, 2025
The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up...
Critical
Unreviewed
CVE-2025-13538
was published
Nov 27, 2025
The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions...
Critical
Unreviewed
CVE-2025-13540
was published
Nov 27, 2025
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
Critical
Unreviewed
CVE-2025-13675
was published
Nov 27, 2025
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
High
Unreviewed
CVE-2025-13680
was published
Nov 27, 2025
Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing...
High
Unreviewed
CVE-2025-66314
was published
Nov 27, 2025
The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the ...
Critical
Unreviewed
CVE-2025-66266
was published
Nov 26, 2025
CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions,...
Moderate
Unreviewed
CVE-2025-66265
was published
Nov 26, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could...
High
Unreviewed
CVE-2025-33188
was published
Nov 25, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged...
Critical
Unreviewed
CVE-2025-33187
was published
Nov 25, 2025
The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
Critical
Unreviewed
CVE-2025-13559
was published
Nov 25, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
An Improper Privilege Management vulnerability [CWE-269] in Fortinet FortiOS 7.6.0 through 7.6.3,...
Low
Unreviewed
CVE-2025-54821
was published
Nov 18, 2025
A missing validation process exists in Serv U when abused, could give a malicious actor with...
Critical
Unreviewed
CVE-2025-40548
was published
Nov 18, 2025
LXD vulnerable to a local privilege escalation through custom storage volumes
High
GHSA-3g2j-vm47-x4mj
was published
for
github.com/canonical/lxd
(Go)
Nov 13, 2025
ProTip!
Advisories are also available from the
GraphQL API