GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
535 advisories
Filter by severity
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user...
High
Unreviewed
CVE-2024-46464
was published
Jan 10, 2025
pgAdmin has Incorrect Default Permissions
High
CVE-2023-1907
was published
for
pgadmin4
(pip)
Jan 9, 2025
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may...
High
Unreviewed
CVE-2023-23583
was published
Nov 14, 2023
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow...
High
Unreviewed
CVE-2023-35080
was published
Nov 15, 2023
When a particular process flow is initiated, an attacker may be able to gain unauthorized...
High
Unreviewed
CVE-2023-41718
was published
Nov 15, 2023
An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated...
High
Unreviewed
CVE-2021-27285
was published
Jan 7, 2025
Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444...
High
Unreviewed
CVE-2023-28739
was published
Jan 7, 2025
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could...
High
Unreviewed
CVE-2024-43769
was published
Jan 3, 2025
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused...
High
Unreviewed
CVE-2024-53841
was published
Jan 3, 2025
there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to...
High
Unreviewed
CVE-2024-11624
was published
Jan 3, 2025
there is a possible biometric bypass due to an unusual root cause. This could lead to local...
High
Unreviewed
CVE-2024-53840
was published
Jan 3, 2025
there is a possible biometric bypass due to an unusual root cause. This could lead to local...
High
Unreviewed
CVE-2024-53835
was published
Jan 3, 2025
EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local...
High
Unreviewed
CVE-2023-32221
was published
Jun 12, 2023
Some Huawei wearables have a permission management vulnerability.
High
Unreviewed
CVE-2021-37000
was published
Dec 28, 2024
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
High
Unreviewed
CVE-2024-52926
was published
Nov 18, 2024
Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A...
High
Unreviewed
CVE-2024-12903
was published
Dec 23, 2024
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned...
High
Unreviewed
CVE-2024-49202
was published
Dec 18, 2024
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00...
High
Unreviewed
CVE-2024-4229
was published
Dec 19, 2024
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and...
High
Unreviewed
CVE-2024-38499
was published
Dec 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44224
was published
Dec 12, 2024
In onResume of AppManagementFragment.java, there is a possible way to prevent users from...
High
Unreviewed
CVE-2023-21121
was published
Jun 15, 2023
In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a...
High
Unreviewed
CVE-2023-21129
was published
Jun 15, 2023
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch...
High
Unreviewed
CVE-2023-21126
was published
Jun 15, 2023
In various functions of AppStandbyController.java, there is a possible way to break manageability...
High
Unreviewed
CVE-2023-21128
was published
Jun 15, 2023
ProTip!
Advisories are also available from the
GraphQL API