GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
503 advisories
Filter by severity
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input...
Moderate
Unreviewed
CVE-2025-22425
was published
Sep 4, 2025
The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-9190
was published
Aug 26, 2025
The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-53813
was published
Aug 26, 2025
The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-53811
was published
Aug 26, 2025
Incorrect default permissions for some Intel(R) Distribution for Python software installers...
Moderate
Unreviewed
CVE-2025-26470
was published
Aug 12, 2025
Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may...
Moderate
Unreviewed
CVE-2025-27559
was published
Aug 12, 2025
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may...
Moderate
Unreviewed
CVE-2025-20087
was published
Aug 12, 2025
Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an...
Moderate
Unreviewed
CVE-2025-20023
was published
Aug 12, 2025
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and...
Moderate
Unreviewed
CVE-2025-8672
was published
Aug 11, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager ...
Moderate
Unreviewed
CVE-2024-39347
was published
Aug 7, 2025
4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.
Moderate
Unreviewed
CVE-2024-55398
was published
Aug 6, 2025
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged...
Moderate
Unreviewed
CVE-2025-41658
was published
Aug 4, 2025
CVE-2025-49082 is a vulnerability in the management console
of Absolute Secure Access prior to...
Moderate
Unreviewed
CVE-2025-49082
was published
Jul 31, 2025
CVE-2025-54085 is a vulnerability in the management console
of Absolute Secure Access prior to...
Moderate
Unreviewed
CVE-2025-54085
was published
Jul 31, 2025
CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to...
Moderate
Unreviewed
CVE-2025-49084
was published
Jul 31, 2025
melange's world-writable permissions expose SBOM files to potential image tampering
Moderate
CVE-2025-54059
was published
for
chainguard.dev/melange
(Go)
Jul 18, 2025
An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the...
Moderate
Unreviewed
CVE-2025-41665
was published
Jul 8, 2025
The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2024-11089
was published
Jul 7, 2025
HashiCorp Vagrant has code injection vulnerability through default synced folders
Moderate
CVE-2025-34075
was published
for
vagrant
(RubyGems)
Jul 2, 2025
filebrowser Sets Insecure File Permissions
Moderate
CVE-2025-52900
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 27, 2025
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local...
Moderate
Unreviewed
CVE-2025-39201
was published
Jun 24, 2025
The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple...
Moderate
Unreviewed
CVE-2025-5963
was published
Jun 20, 2025
The Phoenix Code's configuration on macOS, specifically the presence of entitlements: "com.apple...
Moderate
Unreviewed
CVE-2025-5255
was published
Jun 20, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact
Moderate
CVE-2025-6264
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jun 20, 2025
ProTip!
Advisories are also available from the
GraphQL API