GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
611 advisories
Filter by severity
An incorrect permission assignment for critical resource vulnerability has been reported to...
High
Unreviewed
CVE-2024-38646
was published
Nov 22, 2024
G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-6871
was published
Nov 23, 2024
Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-7245
was published
Nov 23, 2024
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation...
High
Unreviewed
CVE-2024-9245
was published
Nov 23, 2024
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation...
High
Unreviewed
CVE-2024-9244
was published
Nov 23, 2024
Incorrect permission assignment in temporary access requests component in Devolutions Remote...
High
Unreviewed
CVE-2024-12149
was published
Dec 4, 2024
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated...
High
Unreviewed
CVE-2024-10256
was published
Dec 10, 2024
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated...
High
Unreviewed
CVE-2024-7572
was published
Dec 10, 2024
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local...
High
Unreviewed
CVE-2024-8540
was published
Dec 10, 2024
Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24...
High
Unreviewed
CVE-2024-12363
was published
Dec 11, 2024
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application ...
High
Unreviewed
CVE-2024-37574
was published
Dec 4, 2024
A flaw was found in the OpenShift build process, where the docker-build container is configured...
High
Unreviewed
CVE-2024-45497
was published
Dec 31, 2024
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to...
High
Unreviewed
CVE-2024-55411
was published
Jan 7, 2025
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
High
CVE-2024-7594
was published
for
github.com/hashicorp/vault
(Go)
Sep 26, 2024
An authenticated attacker can use this vulnerability to perform a privilege escalation to gain...
High
Unreviewed
CVE-2024-11497
was published
Jan 14, 2025
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21325
was published
Jan 17, 2025
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local...
High
Unreviewed
CVE-2024-9842
was published
Nov 12, 2024
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to
...
High
Unreviewed
CVE-2025-0590
was published
Jan 20, 2025
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation...
High
Unreviewed
CVE-2023-31871
was published
May 18, 2023
A local low-level user on the server machine with credentials to the running OAS services can...
High
Unreviewed
CVE-2024-11220
was published
Dec 6, 2024
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project...
High
Unreviewed
CVE-2024-46881
was published
Jan 26, 2025
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above....
High
Unreviewed
CVE-2025-24481
was published
Jan 28, 2025
An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem...
High
Unreviewed
CVE-2023-29092
was published
May 9, 2023
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-57547
was published
Jan 28, 2025
CVE-2024-7513 IMPACT
A code execution vulnerability exists in the affected product. The...
High
Unreviewed
CVE-2024-7513
was published
Aug 14, 2024
ProTip!
Advisories are also available from the
GraphQL API