GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,462
Erlang
33
GitHub Actions
22
Go
2,159
Maven
5,000+
npm
3,820
NuGet
696
pip
3,502
Pub
12
RubyGems
903
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission...
Moderate
Unreviewed
CVE-2025-20649
was published
Mar 3, 2025
Xuxueli xxl-job allows attacker to obtain sensitive information via the pageList parameter
High
CVE-2023-27087
was published
for
com.xuxueli:xxl-job
(Maven)
Mar 21, 2023
The product does not handle or incorrectly handles when it has insufficient privileges to access...
Moderate
Unreviewed
CVE-2024-6697
was published
Feb 20, 2025
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain...
Critical
Unreviewed
CVE-2024-24116
was published
Oct 2, 2024
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
Moderate
CVE-2024-36112
was published
for
nautobot
(pip)
May 29, 2024
An attacker who successfully exploited these vulnerabilities could cause enable command execution...
High
Unreviewed
CVE-2024-12430
was published
Jan 7, 2025
Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege...
High
Unreviewed
CVE-2025-22395
was published
Jan 7, 2025
Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to...
High
Unreviewed
CVE-2024-43705
was published
Dec 28, 2024
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An...
Low
Unreviewed
CVE-2024-42194
was published
Dec 17, 2024
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the...
High
Unreviewed
CVE-2024-23704
was published
May 7, 2024
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients...
Critical
Unreviewed
CVE-2024-46874
was published
Dec 6, 2024
Software installed and run as a non-privileged user may conduct improper GPU system calls to...
High
Unreviewed
CVE-2024-43702
was published
Nov 30, 2024
there is a possible way to bypass due to a logic error in the code. This could lead to local...
High
Unreviewed
CVE-2024-29748
was published
Apr 5, 2024
Quarkus Improper Handling of Insufficient Permissions or Privileges and Improper Handling of Exceptional Conditions vulnerability
High
CVE-2023-6267
was published
for
io.quarkus.resteasy.reactive:resteasy-reactive
(Maven)
Jan 25, 2024
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4211
was published
Oct 16, 2024
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4692
was published
Oct 16, 2024
In some rare cases, there is a password type validation missing in Revert Password check and for...
High
Unreviewed
CVE-2023-41972
was published
Mar 26, 2024
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass...
Moderate
Unreviewed
CVE-2023-39249
was published
Oct 17, 2024
Pixelfed doesn't check OAuth Scopes in API routes, giving elevated permissions
Critical
CVE-2024-25108
was published
for
pixelfed/pixelfed
(Composer)
Feb 12, 2024
Duplicate Advisory: Apiman has insufficient checks for read permissions
High
GHSA-54r5-wr8x-x5v3
was published
for
io.apiman:apiman-manager-api-rest-impl
(Maven)
Dec 20, 2022
•
withdrawn
Certain switch models from PLANET Technology have an SSH service that improperly handles...
High
Unreviewed
CVE-2024-8451
was published
Sep 30, 2024
Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an...
High
Unreviewed
CVE-2023-43591
was published
Nov 15, 2023
Mautic Sensitive Data Exposure due to inadequate user permission settings
High
CVE-2022-25776
was published
for
mautic/core
(Composer)
Apr 12, 2024
Missing access permissions checks
in the M-Files server before 23.11.13156.0 allow attackers...
Moderate
Unreviewed
CVE-2023-6189
was published
Nov 22, 2023
Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of...
High
Unreviewed
CVE-2023-2480
was published
May 25, 2023
ProTip!
Advisories are also available from the
GraphQL API