GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,781
Erlang
36
GitHub Actions
29
Go
2,345
Maven
5,000+
npm
3,976
NuGet
719
pip
3,772
Pub
12
RubyGems
923
Rust
980
Swift
38
Unreviewed advisories
All unreviewed
5,000+
27 advisories
Filter by severity
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2025-5476
was published
Jun 23, 2025
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7...
Low
Unreviewed
CVE-2024-35281
was published
May 13, 2025
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs,...
Critical
Unreviewed
CVE-2025-4083
was published
Apr 29, 2025
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to...
Moderate
Unreviewed
CVE-2025-3086
was published
Apr 4, 2025
ingress-nginx admission controller RCE escalation
Critical
CVE-2025-1974
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows...
Moderate
Unreviewed
CVE-2025-26393
was published
Mar 17, 2025
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Moderate
CVE-2025-29781
was published
for
github.com/metal3-io/baremetal-operator/apis
(Go)
Mar 17, 2025
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks...
Moderate
Unreviewed
CVE-2025-21590
was published
Mar 12, 2025
Azure PromptFlow remote code execution related to Jinja templates
Moderate
CVE-2025-24986
was published
for
promptflow-core
(pip)
Mar 11, 2025
lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
Moderate
Unreviewed
CVE-2024-55456
was published
Feb 3, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
High
Unreviewed
CVE-2024-0135
was published
Jan 28, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
High
Unreviewed
CVE-2024-0136
was published
Jan 28, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
Moderate
Unreviewed
CVE-2024-0137
was published
Jan 28, 2025
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component...
Moderate
Unreviewed
CVE-2024-57723
was published
Jan 23, 2025
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
Moderate
Unreviewed
CVE-2024-57720
was published
Jan 23, 2025
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component...
Moderate
Unreviewed
CVE-2024-57721
was published
Jan 23, 2025
A user with advanced report application access rights can perform actions for which they are not...
High
Unreviewed
CVE-2024-47520
was published
Jan 11, 2025
vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse...
Moderate
Unreviewed
CVE-2024-35425
was published
Nov 9, 2024
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users...
Moderate
Unreviewed
CVE-2024-8118
was published
Sep 26, 2024
The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRD
Moderate
CVE-2024-43803
was published
for
github.com/metal3-io/baremetal-operator
(Go)
Sep 3, 2024
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2024-20285
was published
Aug 28, 2024
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to...
High
Unreviewed
CVE-2024-6323
was published
Jun 27, 2024
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component...
Critical
Unreviewed
CVE-2024-33768
was published
May 1, 2024
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe)...
Moderate
Unreviewed
CVE-2024-30388
was published
Apr 12, 2024
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files...
High
Unreviewed
CVE-2023-1305
was published
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API