GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,883
Maven
5,000+
npm
4,522
NuGet
785
pip
4,262
Pub
12
RubyGems
975
Rust
1,105
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,396 advisories
Filter by severity
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13...
High
Unreviewed
CVE-2025-24234
was published
Apr 1, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24207
was published
Apr 1, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
Critical
Unreviewed
CVE-2025-24172
was published
Apr 1, 2025
An integer overflow was addressed with improved input validation. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24195
was published
Apr 1, 2025
A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13...
High
Unreviewed
CVE-2025-24170
was published
Apr 1, 2025
The WatchGuard Terminal Services Agent on Windows does not properly configure directory...
Moderate
Unreviewed
CVE-2025-2782
was published
Mar 29, 2025
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory...
Moderate
Unreviewed
CVE-2025-2781
was published
Mar 29, 2025
HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2025-25535
was published
Mar 26, 2025
AWS CDK CodePipeline: trusted entities are too broad
Low
GHSA-5pq3-h73f-66hr
was published
for
aws-cdk-lib
(npm)
Mar 24, 2025
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions...
High
Unreviewed
CVE-2025-24915
was published
Mar 21, 2025
Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66
Moderate
CVE-2025-27612
was published
for
libcontainer
(Rust)
Mar 21, 2025
This issue was addressed through improved state management. This issue is fixed in visionOS 1.3,...
Moderate
Unreviewed
CVE-2024-54564
was published
Mar 21, 2025
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for...
Moderate
Unreviewed
CVE-2024-0245
was published
Mar 20, 2025
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration...
Moderate
Unreviewed
CVE-2025-27926
was published
Mar 11, 2025
Incorrect access permission of a specific service issue exists in RemoteView Agent (for Windows)...
High
Unreviewed
CVE-2025-22447
was published
Mar 6, 2025
Incorrect access permission of a specific folder issue exists in RemoteView Agent (for Windows)...
High
Unreviewed
CVE-2025-24864
was published
Mar 6, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27677
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330...
Critical
Unreviewed
CVE-2025-27682
was published
Mar 5, 2025
Vulnerability of improper access permission in the process management module
Impact: Successful...
Moderate
Unreviewed
CVE-2025-27521
was published
Mar 4, 2025
Vulnerability of improper access permission in the HDC module
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2024-58050
was published
Mar 4, 2025
Permission management vulnerability in the lock screen module
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2024-58046
was published
Mar 4, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an...
Critical
Unreviewed
CVE-2024-56525
was published
Feb 25, 2025
Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission...
Moderate
Unreviewed
CVE-2025-21106
was published
Feb 20, 2025
ProTip!
Advisories are also available from the
GraphQL API