GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,776 advisories
Filter by severity
Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate...
Moderate
Unreviewed
CVE-2024-6908
was published
Jul 19, 2024
Potential vulnerabilities have been identified in the HP Display Control software component...
Moderate
Unreviewed
CVE-2024-24970
was published
Jul 19, 2024
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a...
Moderate
Unreviewed
CVE-2024-34457
was published
Jul 22, 2024
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3...
Moderate
Unreviewed
CVE-2024-1575
was published
Jul 23, 2024
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the...
High
Unreviewed
CVE-2020-11640
was published
Jul 23, 2024
The Argo CD web terminal session does not handle the revocation of user permissions properly
Moderate
CVE-2024-41666
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Jul 24, 2024
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows...
High
Unreviewed
CVE-2023-50700
was published
Jul 26, 2024
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements...
Moderate
Unreviewed
CVE-2024-27357
was published
Jul 26, 2024
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with...
High
Unreviewed
CVE-2024-42050
was published
Jul 28, 2024
RaspAP allows an attacker to escalate privileges
Critical
CVE-2024-41637
was published
for
billz/raspap-webgui
(Composer)
Jul 29, 2024
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to...
Critical
Unreviewed
CVE-2024-37858
was published
Jul 29, 2024
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6...
High
Unreviewed
CVE-2024-27826
was published
Jul 30, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
High
Unreviewed
CVE-2024-40781
was published
Jul 30, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
High
Unreviewed
CVE-2024-40802
was published
Jul 30, 2024
Harbor fails to validate the user permissions when updating project configurations
High
CVE-2024-22278
was published
for
github.com/goharbor/harbor
(Go)
Jul 31, 2024
biscuit-auth vulnerable to public key confusion in third party block
Low
CVE-2024-41949
was published
for
biscuit-auth
(Rust)
Jul 31, 2024
Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation...
High
Unreviewed
CVE-2024-38775
was published
Aug 1, 2024
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows...
High
Unreviewed
CVE-2023-52209
was published
Aug 1, 2024
Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule...
Critical
Unreviewed
CVE-2024-38770
was published
Aug 1, 2024
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows...
High
Unreviewed
CVE-2024-39634
was published
Aug 1, 2024
Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows...
High
Unreviewed
CVE-2024-39633
was published
Aug 1, 2024
Apache Linkis vulnerable to privilege escalation
High
CVE-2024-27181
was published
for
org.apache.linkis:linkis
(Maven)
Aug 2, 2024
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
High
Unreviewed
CVE-2024-33894
was published
Aug 2, 2024
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up...
High
Unreviewed
CVE-2024-7291
was published
Aug 3, 2024
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
High
GHSA-6vjm-54vp-mxhx
was published
for
github.com/juju/juju
(Go)
Aug 5, 2024
ProTip!
Advisories are also available from the
GraphQL API