GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
322 advisories
Filter by severity
Mattermost Desktop App Remote Code Execution
Moderate
CVE-2024-37182
was published
for
mattermost-desktop
(npm)
Jun 14, 2024
Mattermost Desktop App allows for bypassing TCC restrictions on macOS
Low
CVE-2024-36287
was published
for
mattermost-desktop
(npm)
Jun 14, 2024
Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This...
High
Unreviewed
CVE-2024-6153
was published
Jun 20, 2024
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
High
CVE-2024-34144
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 2, 2024
Sandbox bypass in Script Security Plugin
Critical
CVE-2019-1003029
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 13, 2022
Due to a Protection Mechanism Failure in SAP
NetWeaver Application Server for ABAP and ABAP...
Moderate
Unreviewed
CVE-2024-39599
was published
Jul 9, 2024
Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-38070
was published
Jul 9, 2024
Azure CycleCloud Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38092
was published
Jul 9, 2024
BitLocker Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-38058
was published
Jul 9, 2024
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote...
High
Unreviewed
CVE-2024-27713
was published
Jul 5, 2024
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed....
Moderate
Unreviewed
CVE-2024-6741
was published
Jul 15, 2024
Sandbox bypass in Jenkins Pipeline: Groovy Plugin
Critical
CVE-2019-1003030
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
May 13, 2022
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2023-42918
was published
Jul 29, 2024
ejs lacks certain pollution protection
Moderate
CVE-2024-33883
was published
for
ejs
(npm)
Apr 28, 2024
Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when...
Critical
Unreviewed
CVE-2024-25091
was published
Mar 1, 2024
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter,...
High
Unreviewed
CVE-2024-0101
was published
Aug 8, 2024
Windows SmartScreen Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-38180
was published
Aug 13, 2024
Windows Mark of the Web Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-38213
was published
Aug 13, 2024
Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network...
High
Unreviewed
CVE-2024-23499
was published
Aug 14, 2024
Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and...
High
Unreviewed
CVE-2024-24983
was published
Aug 14, 2024
Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may...
Moderate
Unreviewed
CVE-2024-24980
was published
Aug 14, 2024
Mattermost allows remote/synthetic users to create sessions, reset passwords
Moderate
CVE-2024-39836
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 22, 2024
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2024-20286
was published
Aug 28, 2024
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2024-20284
was published
Aug 28, 2024
Windows Remote Desktop Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2023-35352
was published
Jul 11, 2023
ProTip!
Advisories are also available from the
GraphQL API