GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,056
Erlang
29
GitHub Actions
19
Go
1,889
Maven
5,000+
npm
3,618
NuGet
638
pip
3,231
Pub
10
RubyGems
854
Rust
817
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,091 advisories
Filter by severity
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a...
High
Unreviewed
CVE-2024-27442
was published
Aug 12, 2024
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product...
High
Unreviewed
CVE-2024-22069
was published
Aug 8, 2024
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain...
High
Unreviewed
CVE-2024-43199
was published
Aug 7, 2024
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
High
GHSA-6vjm-54vp-mxhx
was published
for
github.com/juju/juju
(Go)
Aug 5, 2024
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up...
High
Unreviewed
CVE-2024-7291
was published
Aug 3, 2024
Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
High
Unreviewed
CVE-2024-33894
was published
Aug 2, 2024
Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows...
High
Unreviewed
CVE-2024-39633
was published
Aug 1, 2024
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows...
High
Unreviewed
CVE-2024-39634
was published
Aug 1, 2024
Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation...
High
Unreviewed
CVE-2024-38775
was published
Aug 1, 2024
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows...
High
Unreviewed
CVE-2023-52209
was published
Aug 1, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
High
Unreviewed
CVE-2024-40802
was published
Jul 30, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
High
Unreviewed
CVE-2024-40781
was published
Jul 30, 2024
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6...
High
Unreviewed
CVE-2024-27826
was published
Jul 30, 2024
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with...
High
Unreviewed
CVE-2024-42050
was published
Jul 28, 2024
Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows...
High
Unreviewed
CVE-2023-50700
was published
Jul 26, 2024
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the...
High
Unreviewed
CVE-2020-11640
was published
Jul 23, 2024
Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege...
High
Unreviewed
CVE-2024-37560
was published
Jul 12, 2024
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix...
High
Unreviewed
CVE-2024-6286
was published
Jul 10, 2024
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual...
High
Unreviewed
CVE-2024-6151
was published
Jul 10, 2024
Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8...
High
Unreviewed
CVE-2024-3325
was published
Jul 10, 2024
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due...
High
Unreviewed
CVE-2024-34725
was published
Jul 9, 2024
In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution...
High
Unreviewed
CVE-2024-23711
was published
Jul 9, 2024
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion...
High
Unreviewed
CVE-2024-31320
was published
Jul 9, 2024
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without...
High
Unreviewed
CVE-2024-31318
was published
Jul 9, 2024
In onCreate of multiple files, there is a possible way to trick the user into granting health...
High
Unreviewed
CVE-2024-31323
was published
Jul 9, 2024
ProTip!
Advisories are also available from the
GraphQL API