GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,300 advisories
Filter by severity
A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to...
High
Unreviewed
CVE-2025-13292
was published
Dec 6, 2025
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An...
High
Unreviewed
CVE-2025-7044
was published
Dec 3, 2025
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
High
Unreviewed
CVE-2025-59697
was published
Dec 2, 2025
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and...
High
Unreviewed
CVE-2025-13680
was published
Nov 27, 2025
Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing...
High
Unreviewed
CVE-2025-66314
was published
Nov 27, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could...
High
Unreviewed
CVE-2025-33188
was published
Nov 25, 2025
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is...
High
Unreviewed
CVE-2025-11923
was published
Nov 13, 2025
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to...
High
Unreviewed
CVE-2025-59514
was published
Nov 11, 2025
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001...
High
Unreviewed
CVE-2025-24838
was published
Nov 11, 2025
The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up...
High
Unreviewed
CVE-2025-11168
was published
Nov 11, 2025
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed...
High
Unreviewed
CVE-2025-12726
was published
Nov 10, 2025
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC...
High
Unreviewed
CVE-2025-12405
was published
Nov 10, 2025
Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025.3.5.0 and...
High
Unreviewed
CVE-2025-12485
was published
Nov 6, 2025
The service employed by Everything, running as SYSTEM, communicates with the lower privileged...
High
Unreviewed
CVE-2025-12683
was published
Nov 4, 2025
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if...
High
Unreviewed
CVE-2025-48982
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to...
High
Unreviewed
CVE-2024-14004
was published
Oct 31, 2025
An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate...
High
Unreviewed
CVE-2025-61429
was published
Oct 29, 2025
By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with...
High
Unreviewed
CVE-2025-1037
was published
Oct 28, 2025
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is...
High
Unreviewed
CVE-2025-11086
was published
Oct 22, 2025
An attacker may obtain the root shell on the underlying OS system with the restricted conditions...
High
Unreviewed
CVE-2025-7851
was published
Oct 21, 2025
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for...
High
Unreviewed
CVE-2025-6042
was published
Oct 15, 2025
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx....
High
Unreviewed
CVE-2025-9067
was published
Oct 14, 2025
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer...
High
Unreviewed
CVE-2025-9068
was published
Oct 14, 2025
Azure PlayFab Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-59247
was published
Oct 9, 2025
A flaw was found in the integration of Active Directory and the System Security Services Daemon ...
High
Unreviewed
CVE-2025-11561
was published
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API