GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,386
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,480
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
273 advisories
Filter by severity
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
Moderate
CVE-2023-28668
was published
for
org.jenkins-ci.plugins:role-strategy
(Maven)
Apr 2, 2023
Insufficient macro permission validation of The Document Foundation LibreOffice allows an...
High
Unreviewed
CVE-2023-6186
was published
Dec 11, 2023
System files could be overwritten using the less command in Brocade Fabric OS before Brocade...
High
Unreviewed
CVE-2023-31926
was published
Aug 2, 2023
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android...
Moderate
Unreviewed
CVE-2024-36062
was published
Nov 8, 2024
EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0 are vulnerable to Incorrect Access Control. This...
High
Unreviewed
CVE-2024-53355
was published
Feb 1, 2025
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.7...
High
Unreviewed
CVE-2024-54557
was published
Jan 28, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2024-54516
was published
Jan 28, 2025
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server...
Moderate
Unreviewed
CVE-2024-52869
was published
Jan 8, 2025
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-24087
was published
Jan 28, 2025
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and...
High
Unreviewed
CVE-2022-26024
was published
Nov 11, 2022
RuoYi vulnerable to Denial of Service by attackers with admin privileges
Moderate
CVE-2024-57439
was published
for
com.ruoyi:ruoyi
(Maven)
Jan 29, 2025
snowflake-sdk may incorrectly validate temporary credential cache file permissions
Moderate
CVE-2025-24791
was published
for
snowflake-sdk
(npm)
Jan 29, 2025
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki
High
CVE-2021-3978
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 19, 2021
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the...
Moderate
Unreviewed
CVE-2024-56178
was published
Jan 28, 2025
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections...
High
Unreviewed
CVE-2024-40672
was published
Jan 28, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42231
was published
Jan 14, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42228
was published
Jan 14, 2025
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens...
Moderate
Unreviewed
CVE-2025-21541
was published
Jan 21, 2025
Vulnerability in the Oracle Communications Order and Service Management product of Oracle...
Moderate
Unreviewed
CVE-2025-21544
was published
Jan 21, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
Insecure default config access in WriteFreely
High
CVE-2025-24337
was published
for
github.com/writefreely/writefreely
(Go)
Jan 20, 2025
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to...
Critical
Unreviewed
CVE-2024-46310
was published
Jan 13, 2025
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access...
High
Unreviewed
CVE-2024-54818
was published
Jan 8, 2025
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes)...
High
Unreviewed
CVE-2024-53934
was published
Jan 7, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54879
was published
Jan 6, 2025
ProTip!
Advisories are also available from the
GraphQL API