GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,023
Erlang
29
GitHub Actions
16
Go
1,830
Maven
5,000+
npm
3,573
NuGet
632
pip
3,156
Pub
10
RubyGems
847
Rust
796
Swift
34
Unreviewed advisories
All unreviewed
5,000+
73 advisories
Filter by severity
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19...
High
Unreviewed
CVE-2024-41139
was published
Jul 29, 2024
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate...
High
Unreviewed
CVE-2024-40433
was published
Jul 27, 2024
An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can...
Critical
Unreviewed
CVE-2024-23794
was published
Jul 15, 2024
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM...
High
Unreviewed
CVE-2024-38278
was published
Jul 9, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment...
Moderate
Unreviewed
CVE-2024-37132
was published
Jul 2, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management...
Moderate
Unreviewed
CVE-2024-37134
was published
Jul 2, 2024
IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under...
High
Unreviewed
CVE-2024-31912
was published
Jun 28, 2024
An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker...
Moderate
Unreviewed
CVE-2023-7270
was published
Jun 27, 2024
XWiki Platform allows remote code execution from user account
Critical
CVE-2024-37899
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 20, 2024
NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users...
Moderate
Unreviewed
CVE-2024-0085
was published
Jun 14, 2024
Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to...
High
Unreviewed
CVE-2024-36587
was published
Jun 13, 2024
In the Linux kernel, the following vulnerability has been resolved:
ethtool: strset: fix message...
High
Unreviewed
CVE-2021-47241
was published
May 21, 2024
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could...
High
Unreviewed
CVE-2024-20389
was published
May 16, 2024
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could...
High
Unreviewed
CVE-2024-27273
was published
May 7, 2024
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted...
High
Unreviewed
CVE-2024-27453
was published
May 3, 2024
Kubelet Incorrect Privilege Assignment
Moderate
CVE-2019-11245
was published
for
k8s.io/kubernetes/cmd/kubelet
(Go)
Apr 24, 2024
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI...
High
Unreviewed
CVE-2023-38298
was published
Apr 22, 2024
An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges...
Moderate
Unreviewed
CVE-2024-31760
was published
Apr 17, 2024
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers...
High
Unreviewed
CVE-2024-20320
was published
Mar 13, 2024
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be...
Moderate
Unreviewed
CVE-2024-23976
was published
Feb 14, 2024
Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R...
Moderate
Unreviewed
CVE-2023-6815
was published
Feb 13, 2024
The FACSChorus software does not properly assign data access privileges for operating system user...
Low
Unreviewed
CVE-2023-29066
was published
Nov 28, 2023
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The...
High
Unreviewed
CVE-2023-5913
was published
Nov 8, 2023
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and...
High
Unreviewed
CVE-2023-4153
was published
Sep 13, 2023
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to...
High
Unreviewed
CVE-2020-10129
was published
Sep 6, 2023
ProTip!
Advisories are also available from the
GraphQL API