GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,764 advisories
Filter by severity
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the...
Critical
Unreviewed
CVE-2025-6934
was published
Jul 1, 2025
Janssen Config API returns results without scope verification
High
CVE-2025-53003
was published
for
io.jans:jans-config-api-server
(Maven)
Jun 30, 2025
An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows...
Moderate
Unreviewed
CVE-2025-45737
was published
Jun 27, 2025
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all...
Critical
Unreviewed
CVE-2025-4334
was published
Jun 26, 2025
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated,...
Critical
Unreviewed
CVE-2025-20282
was published
Jun 26, 2025
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC)....
High
Unreviewed
CVE-2025-37101
was published
Jun 26, 2025
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An...
High
Unreviewed
CVE-2025-39202
was published
Jun 24, 2025
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to...
High
Unreviewed
CVE-2023-50450
was published
Jun 23, 2025
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup...
High
Unreviewed
CVE-2025-24286
was published
Jun 19, 2025
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local...
High
Unreviewed
CVE-2025-49156
was published
Jun 17, 2025
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a...
High
Unreviewed
CVE-2025-49157
was published
Jun 17, 2025
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix...
High
Unreviewed
CVE-2025-0320
was published
Jun 17, 2025
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix...
High
Unreviewed
CVE-2025-4879
was published
Jun 17, 2025
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled...
High
Unreviewed
CVE-2025-6177
was published
Jun 16, 2025
New authd users logging in via SSH are members of the root group
Moderate
CVE-2025-5689
was published
for
github.com/ubuntu/authd
(Go)
Jun 16, 2025
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non...
High
Unreviewed
CVE-2025-36631
was published
Jun 13, 2025
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non...
High
Unreviewed
CVE-2025-36633
was published
Jun 13, 2025
Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows...
High
Unreviewed
CVE-2025-5491
was published
Jun 13, 2025
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege...
High
Unreviewed
CVE-2025-4315
was published
Jun 11, 2025
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.
...
High
Unreviewed
CVE-2025-5687
was published
Jun 11, 2025
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0...
High
Unreviewed
CVE-2025-47713
was published
Jun 11, 2025
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0...
High
Unreviewed
CVE-2025-47849
was published
Jun 11, 2025
The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0....
Low
Unreviewed
CVE-2025-22829
was published
Jun 11, 2025
Improper privilege management in Windows Remote Access Connection Manager allows an authorized...
High
Unreviewed
CVE-2025-47955
was published
Jun 10, 2025
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-33067
was published
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API