GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,829
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,065
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,242 advisories
Filter by severity
External Secrets Operator's Missing Namespace Restriction Allows Unauthorized Secret Access
High
CVE-2025-55196
was published
for
github.com/external-secrets/external-secrets
(Go)
Aug 13, 2025
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an...
High
Unreviewed
CVE-2025-48860
was published
Aug 14, 2025
A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown...
High
Unreviewed
CVE-2025-8762
was published
Aug 13, 2025
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-53729
was published
Aug 12, 2025
Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe...
High
Unreviewed
CVE-2025-24323
was published
Aug 12, 2025
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a...
High
Unreviewed
CVE-2025-24999
was published
Aug 12, 2025
Improper access control in Azure Virtual Machines allows an authorized attacker to perform...
High
Unreviewed
CVE-2025-49707
was published
Aug 12, 2025
Incorrect access control in Sage DPW v2024.12.003 allows unauthorized attackers to access the...
High
Unreviewed
CVE-2025-51532
was published
Aug 6, 2025
Memory corruption while handling client exceptions, allowing unauthorized channel access.
High
Unreviewed
CVE-2025-27062
was published
Aug 6, 2025
NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver,...
High
Unreviewed
CVE-2025-23277
was published
Aug 3, 2025
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential...
High
Unreviewed
CVE-2025-50850
was published
Jul 31, 2025
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3,...
High
Unreviewed
CVE-2025-29556
was published
Jul 31, 2025
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02)...
High
Unreviewed
CVE-2025-50777
was published
Jul 30, 2025
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-43270
was published
Jul 30, 2025
An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and...
High
Unreviewed
CVE-2024-42655
was published
Jul 29, 2025
Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows...
High
Unreviewed
CVE-2023-31100
was published
Nov 15, 2023
An issue in Gardyn 4 allows a remote attacker with the corresponding ssh private key can gain...
High
Unreviewed
CVE-2025-29630
was published
Jul 25, 2025
Improper access control in secure message component in Devolutions Server allows an authenticated...
High
Unreviewed
CVE-2025-6741
was published
Jul 22, 2025
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139...
High
Unreviewed
CVE-2025-46118
was published
Jul 21, 2025
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker...
High
Unreviewed
CVE-2025-23083
was published
Jan 22, 2025
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2025-50105
was published
Jul 15, 2025
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). ...
High
Unreviewed
CVE-2025-50060
was published
Jul 15, 2025
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
High
Unreviewed
CVE-2025-50059
was published
Jul 15, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-53028
was published
Jul 15, 2025
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of...
High
Unreviewed
CVE-2024-10366
was published
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API