GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
261 advisories
Filter by severity
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens...
Moderate
Unreviewed
CVE-2025-21541
was published
Jan 21, 2025
Vulnerability in the Oracle Communications Order and Service Management product of Oracle...
Moderate
Unreviewed
CVE-2025-21544
was published
Jan 21, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
Insecure default config access in WriteFreely
High
CVE-2025-24337
was published
for
github.com/writefreely/writefreely
(Go)
Jan 20, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42228
was published
Jan 14, 2025
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low...
High
Unreviewed
CVE-2023-42231
was published
Jan 14, 2025
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to...
Critical
Unreviewed
CVE-2024-46310
was published
Jan 13, 2025
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access...
High
Unreviewed
CVE-2024-54818
was published
Jan 8, 2025
The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes)...
High
Unreviewed
CVE-2024-53934
was published
Jan 7, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54879
was published
Jan 6, 2025
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software...
Critical
Unreviewed
CVE-2024-46622
was published
Jan 6, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54880
was published
Jan 6, 2025
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2024-55507
was published
Jan 3, 2025
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44211
was published
Dec 20, 2024
This issue was addressed with improved validation of the process entitlement and Team ID. This...
High
Unreviewed
CVE-2023-42867
was published
Dec 20, 2024
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2024-44223
was published
Dec 20, 2024
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes...
High
Unreviewed
CVE-2024-56317
was published
Dec 19, 2024
Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before...
Moderate
Unreviewed
CVE-2024-37649
was published
Dec 19, 2024
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia...
Critical
Unreviewed
CVE-2024-54465
was published
Dec 12, 2024
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2...
High
Unreviewed
CVE-2024-54515
was published
Dec 12, 2024
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app...
Moderate
Unreviewed
CVE-2024-54484
was published
Dec 12, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 11...
Moderate
Unreviewed
CVE-2024-54513
was published
Dec 12, 2024
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
High
Unreviewed
CVE-2024-50930
was published
Dec 10, 2024
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
Moderate
Unreviewed
CVE-2024-50931
was published
Dec 10, 2024
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers...
High
Unreviewed
CVE-2024-50920
was published
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API