GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,633
Erlang
34
GitHub Actions
25
Go
2,241
Maven
5,000+
npm
3,902
NuGet
701
pip
3,669
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,274 advisories
Filter by severity
Overview
The product specifies permissions for a security-critical resource in a way that...
Moderate
Unreviewed
CVE-2025-0758
was published
Apr 17, 2025
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search...
High
Unreviewed
CVE-2025-30708
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-30688
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-30687
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). ...
Moderate
Unreviewed
CVE-2025-30684
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). ...
Moderate
Unreviewed
CVE-2025-30685
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-30682
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported...
Moderate
Unreviewed
CVE-2025-21584
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-21585
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). ...
Moderate
Unreviewed
CVE-2025-30683
was published
Apr 15, 2025
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected...
Moderate
Unreviewed
CVE-2025-21578
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Moderate
Unreviewed
CVE-2025-21579
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-21581
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported...
Moderate
Unreviewed
CVE-2025-21580
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported...
Moderate
Unreviewed
CVE-2025-21583
was published
Apr 15, 2025
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux)...
High
Unreviewed
CVE-2024-13861
was published
Apr 11, 2025
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow...
Moderate
Unreviewed
CVE-2025-25041
was published
Apr 1, 2025
In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the ...
Low
Unreviewed
CVE-2025-20233
was published
Mar 27, 2025
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions,...
Critical
Unreviewed
CVE-2025-25373
was published
Mar 25, 2025
An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in...
High
Unreviewed
CVE-2024-10209
was published
Mar 25, 2025
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged...
High
Unreviewed
CVE-2025-27688
was published
Mar 18, 2025
Below has Incorrect Permission Assignment for Critical Resource
High
CVE-2025-27591
was published
for
below
(Rust)
Mar 11, 2025
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a...
High
Unreviewed
CVE-2025-22454
was published
Mar 11, 2025
There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a...
High
Unreviewed
CVE-2025-1067
was published
Feb 25, 2025
ProTip!
Advisories are also available from the
GraphQL API