GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,090
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
65 advisories
Filter by severity
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code...
Critical
Unreviewed
CVE-2023-4662
was published
Sep 15, 2023
A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which...
High
Unreviewed
CVE-2023-4814
was published
Sep 14, 2023
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering...
Critical
Unreviewed
CVE-2023-31175
was published
Aug 31, 2023
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation...
Moderate
Unreviewed
CVE-2023-20217
was published
Aug 17, 2023
Dell PowerScale OneFS 9.5.x version contain a privilege escalation vulnerability. A low...
High
Unreviewed
CVE-2023-32486
was published
Aug 16, 2023
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). The affected...
High
Unreviewed
CVE-2023-38641
was published
Aug 8, 2023
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
High
Unreviewed
CVE-2023-39261
was published
Jul 26, 2023
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate...
Moderate
Unreviewed
CVE-2023-20210
was published
Jul 12, 2023
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo...
High
Unreviewed
CVE-2022-40182
was published
Jul 6, 2023
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution...
High
Unreviewed
CVE-2023-25521
was published
Jul 4, 2023
A vulnerability was found in the HCI sockets implementation due to a missing capability check in...
Moderate
Unreviewed
CVE-2023-2002
was published
May 26, 2023
Wings vulnerable to escape to host from installation container
Critical
CVE-2023-32080
was published
for
github.com/pterodactyl/wings
(Go)
May 11, 2023
Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges...
Critical
Unreviewed
CVE-2023-1966
was published
Apr 28, 2023
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be...
High
Unreviewed
CVE-2023-0664
was published
Mar 29, 2023
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12,...
High
Unreviewed
CVE-2022-3088
was published
Nov 29, 2022
Execution with Unnecessary Privileges in JupyterApp
High
CVE-2022-39286
was published
for
jupyter-core
(pip)
Oct 26, 2022
An attacker may be able to execute malicious actions due to the lack of device access protections...
Critical
Unreviewed
CVE-2022-2634
was published
Aug 11, 2022
Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with...
High
Unreviewed
CVE-2022-1744
was published
Jun 25, 2022
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for...
Critical
Unreviewed
CVE-2021-41035
was published
May 24, 2022
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM...
High
Unreviewed
CVE-2021-37174
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura...
High
Unreviewed
CVE-2021-25651
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura...
High
Unreviewed
CVE-2021-25650
was published
May 24, 2022
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
High
Unreviewed
CVE-2021-1528
was published
May 24, 2022
The software performs an operation at a privilege level higher than the minimum level required,...
High
Unreviewed
CVE-2021-27454
was published
May 24, 2022
A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4)....
High
Unreviewed
CVE-2020-10056
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API