GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      15 advisories
        Filter by severity
        
      
      
    
                    
                      A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27396
                      
                      was published
                      Mar 11, 2025 
                    
                  
                    
                      A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-1003
                      
                      was published
                      Feb 4, 2025 
                    
                  
                    
                      Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-21399
                      
                      was published
                      Jan 17, 2025 
                    
                  
                    
                      The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-38813
                      
                      was published
                      Sep 17, 2024 
                    
                  
                    
                      Internal browser event interfaces were exposed to web content when privileged EventHandler...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-8382
                      
                      was published
                      Sep 3, 2024 
                    
                  
                    
                      For migration as well as to work around kernels unaware of L1TF (see
XSA-273), PV guests may be...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-34322
                      
                      was published
                      Jan 5, 2024 
                    
                  
                    
                      Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5369
                      
                      was published
                      Oct 4, 2023 
                    
                  
                    
                      In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-35692
                      
                      was published
                      Jul 14, 2023 
                    
                  
                    
                      A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0358
                      
                      was published
                      Aug 29, 2022 
                    
                  
                    
                      An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-36762
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-20044
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-18276
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2015-0278
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-16466
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2018-8599
                      
                      was published
                      May 13, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API