GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
119 advisories
Filter by severity
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access...
High
Unreviewed
CVE-2024-54818
was published
Jan 8, 2025
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes)...
High
Unreviewed
CVE-2024-53934
was published
Jan 7, 2025
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44211
was published
Dec 20, 2024
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes...
High
Unreviewed
CVE-2024-56317
was published
Dec 19, 2024
This issue was addressed with improved validation of the process entitlement and Team ID. This...
High
Unreviewed
CVE-2023-42867
was published
Dec 20, 2024
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2...
High
Unreviewed
CVE-2024-54515
was published
Dec 12, 2024
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
High
Unreviewed
CVE-2024-50930
was published
Dec 10, 2024
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v...
High
Unreviewed
CVE-2024-41650
was published
Dec 7, 2024
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v...
High
Unreviewed
CVE-2024-41648
was published
Dec 7, 2024
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers...
High
Unreviewed
CVE-2024-50920
was published
Dec 10, 2024
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed...
High
Unreviewed
CVE-2024-37575
was published
Dec 4, 2024
A permissions issue was addressed by removing vulnerable code and adding additional checks. This...
High
Unreviewed
CVE-2024-27888
was published
Jul 30, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 10...
High
Unreviewed
CVE-2024-40805
was published
Jul 30, 2024
Vulnerability of permission verification in the content sharing pop-up module.Successful...
High
Unreviewed
CVE-2023-52373
was published
Feb 18, 2024
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM...
High
Unreviewed
CVE-2023-34672
was published
Jun 23, 2023
Missing permission checks on Hazelcast client protocol
High
CVE-2023-45859
was published
for
com.hazelcast:hazelcast
(Maven)
Feb 27, 2024
vantage6 vulnerable to Improper Preservation of Permissions
High
CVE-2023-22738
was published
for
vantage6
(pip)
Feb 28, 2023
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or ...
High
Unreviewed
CVE-2024-10458
was published
Oct 29, 2024
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions ...
High
Unreviewed
CVE-2022-38473
was published
Dec 22, 2022
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44149
was published
Sep 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-40770
was published
Sep 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-27795
was published
Sep 17, 2024
Podman publishes a malicious image to public registries
High
CVE-2022-1227
was published
for
github.com/containers/podman/v3
(Go)
Apr 30, 2022
Improper Preservation of Permissions in xxl-job
High
CVE-2024-42681
was published
for
com.xuxueli:xxl-job-core
(Maven)
Aug 15, 2024
Grafana folders admin only permission privilege escalation
High
CVE-2022-36062
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API