GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
406 advisories
Filter by severity
Hashicorp Vault has Privilege Escalation Vulnerability
High
CVE-2025-5999
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6...
Moderate
Unreviewed
CVE-2025-43260
was published
Jul 30, 2025
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on...
Moderate
Unreviewed
CVE-2025-2179
was published
Jul 29, 2025
A vulnerability was found in Vaelsys 4.1.0 and classified as critical. This issue affects some...
Moderate
Unreviewed
CVE-2025-8261
was published
Jul 28, 2025
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1...
High
Unreviewed
CVE-2025-8181
was published
Jul 26, 2025
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to...
Moderate
Unreviewed
CVE-2025-31513
was published
Jul 22, 2025
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-7947
was published
Jul 22, 2025
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in...
Critical
Unreviewed
CVE-2025-44655
was published
Jul 21, 2025
Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce...
Critical
Unreviewed
CVE-2025-52836
was published
Jul 16, 2025
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and...
Moderate
Unreviewed
CVE-2025-7576
was published
Jul 14, 2025
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-7552
was published
Jul 14, 2025
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on...
Moderate
Unreviewed
CVE-2025-0140
was published
Jul 10, 2025
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital...
Moderate
Unreviewed
CVE-2025-0139
was published
Jul 10, 2025
The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can...
Moderate
Unreviewed
CVE-2025-27028
was published
Jul 9, 2025
Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation...
High
Unreviewed
CVE-2025-47422
was published
Jul 8, 2025
SAPCAR allows an attacker logged in with high privileges to override the permissions of the...
Moderate
Unreviewed
CVE-2025-43001
was published
Jul 8, 2025
SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in...
Moderate
Unreviewed
CVE-2025-42992
was published
Jul 8, 2025
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-7076
was published
Jul 6, 2025
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege...
Critical
Unreviewed
CVE-2025-49867
was published
Jul 4, 2025
Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege...
Critical
Unreviewed
CVE-2025-23970
was published
Jul 4, 2025
The misconfiguration in the sudoers configuration of the operating system in
Infinera G42...
High
Unreviewed
CVE-2025-27021
was published
Jul 2, 2025
Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb...
Critical
Unreviewed
CVE-2025-45006
was published
Jul 1, 2025
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60...
Moderate
Unreviewed
CVE-2025-6765
was published
Jun 27, 2025
Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types allows...
High
Unreviewed
CVE-2025-52726
was published
Jun 27, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing Import Page component
Low
CVE-2025-6735
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API