GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
117 advisories
Filter by severity
Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x...
Moderate
Unreviewed
CVE-2025-22890
was published
Feb 6, 2025
IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated...
High
Unreviewed
CVE-2024-49814
was published
Feb 6, 2025
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS...
Low
Unreviewed
CVE-2025-20185
was published
Feb 5, 2025
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes...
Moderate
Unreviewed
CVE-2023-37412
was published
Jan 29, 2025
Apache Solr vulnerable to Execution with Unnecessary Privileges
High
CVE-2025-24814
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
Submariner Operator sets unnecessary RBAC permissions
Moderate
CVE-2024-5042
was published
for
github.com/submariner-io/submariner-operator
(Go)
May 17, 2024
Apache Airflow vulnerable to Execution with Unnecessary Privileges
High
CVE-2024-45034
was published
for
apache-airflow
(pip)
Sep 7, 2024
Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,...
Moderate
Unreviewed
CVE-2024-28005
was published
Mar 28, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
Critical
Unreviewed
CVE-2024-1626
was published
Apr 16, 2024
OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer
Moderate
CVE-2024-7387
was published
for
github.com/openshift/builder
(Go)
Sep 17, 2024
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges...
High
Unreviewed
CVE-2024-47978
was published
Dec 25, 2024
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate...
High
Unreviewed
CVE-2024-35141
was published
Dec 19, 2024
IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1
contains a local...
High
Unreviewed
CVE-2024-31891
was published
Dec 14, 2024
The www-data user can elevate its privileges because sudo is configured to allow the execution of...
High
Unreviewed
CVE-2024-28139
was published
Dec 11, 2024
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a...
Moderate
Unreviewed
CVE-2024-28140
was published
Dec 11, 2024
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated...
High
Unreviewed
CVE-2024-49804
was published
Nov 29, 2024
Possible improper input validation Vulnerability
in iManager has been discovered in
OpenText™...
Moderate
Unreviewed
CVE-2021-38118
was published
Nov 22, 2024
A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the...
High
Unreviewed
CVE-2024-11075
was published
Nov 19, 2024
A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could...
High
Unreviewed
CVE-2020-26074
was published
Nov 18, 2024
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible
Moderate
CVE-2020-10684
was published
for
ansible
(pip)
Apr 7, 2021
Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in...
High
Unreviewed
CVE-2024-8781
was published
Nov 18, 2024
A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of...
Moderate
Unreviewed
CVE-2024-51722
was published
Nov 12, 2024
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an...
High
Unreviewed
CVE-2024-48837
was published
Nov 12, 2024
Attackers with local access to the medical office computer can
escalate their Windows user...
High
Unreviewed
CVE-2024-50590
was published
Nov 8, 2024
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone...
Moderate
Unreviewed
CVE-2024-20420
was published
Oct 16, 2024
ProTip!
Advisories are also available from the
GraphQL API