GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,722
Erlang
35
GitHub Actions
29
Go
2,306
Maven
5,000+
npm
3,947
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
20 advisories
Filter by severity
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
The SSH service of PowerStation from HGiga has a Chroot Escape vulnerability, allowing attackers...
Critical
Unreviewed
CVE-2025-3364
was published
Apr 8, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0...
Critical
Unreviewed
CVE-2024-7102
was published
Feb 13, 2025
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The...
Critical
Unreviewed
CVE-2024-8767
was published
Sep 17, 2024
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information...
Critical
Unreviewed
CVE-2024-35783
was published
Sep 10, 2024
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account...
Critical
Unreviewed
CVE-2024-42024
was published
Sep 7, 2024
Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a...
Critical
Unreviewed
CVE-2024-6913
was published
Jul 22, 2024
A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected...
Critical
Unreviewed
CVE-2024-6834
was published
Jul 17, 2024
Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS...
Critical
Unreviewed
CVE-2024-3330
was published
Jun 27, 2024
Toshiba printers use SNMP for configuration. Using the private community, it is possible to...
Critical
Unreviewed
CVE-2024-27143
was published
Jun 14, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
Critical
Unreviewed
CVE-2024-1626
was published
Apr 16, 2024
An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-23743
was published
Jan 28, 2024
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE)...
Critical
Unreviewed
CVE-2023-52030
was published
Jan 11, 2024
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code...
Critical
Unreviewed
CVE-2023-4662
was published
Sep 15, 2023
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering...
Critical
Unreviewed
CVE-2023-31175
was published
Aug 31, 2023
Wings vulnerable to escape to host from installation container
Critical
CVE-2023-32080
was published
for
github.com/pterodactyl/wings
(Go)
May 11, 2023
Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges...
Critical
Unreviewed
CVE-2023-1966
was published
Apr 28, 2023
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0...
Critical
Unreviewed
CVE-2022-44544
was published
Nov 6, 2022
An attacker may be able to execute malicious actions due to the lack of device access protections...
Critical
Unreviewed
CVE-2022-2634
was published
Aug 11, 2022
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for...
Critical
Unreviewed
CVE-2021-41035
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API