GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component:...
Moderate
Unreviewed
CVE-2025-62289
was published
Oct 21, 2025
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component:...
Low
Unreviewed
CVE-2025-62480
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
Moderate
Unreviewed
CVE-2025-62591
was published
Oct 21, 2025
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block...
Low
Unreviewed
CVE-2025-62479
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-62589
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-62590
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-62588
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-62641
was published
Oct 21, 2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). ...
High
Unreviewed
CVE-2025-62587
was published
Oct 21, 2025
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API)...
Moderate
Unreviewed
CVE-2025-61754
was published
Oct 21, 2025
Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health...
Moderate
Unreviewed
CVE-2025-62288
was published
Oct 21, 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The...
Moderate
Unreviewed
CVE-2025-53070
was published
Oct 21, 2025
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A...
High
Unreviewed
CVE-2025-41244
was published
Sep 29, 2025
A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6...
Moderate
Unreviewed
CVE-2025-7691
was published
Sep 26, 2025
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
High
CVE-2025-26467
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Aug 25, 2025
In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port...
Moderate
Unreviewed
CVE-2025-47811
was published
Jul 10, 2025
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA)...
Moderate
Unreviewed
CVE-2025-7030
was published
Jul 8, 2025
An attacker with knowledge of creating user accounts during VM deployment on Google Cloud...
High
Unreviewed
CVE-2025-2903
was published
Apr 17, 2025
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
High
CVE-2025-23015
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service,...
High
Unreviewed
CVE-2024-55968
was published
Jan 29, 2025
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local...
High
Unreviewed
CVE-2024-8539
was published
Nov 12, 2024
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated...
High
Unreviewed
CVE-2024-7571
was published
Nov 12, 2024
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local...
High
Unreviewed
CVE-2024-9842
was published
Nov 12, 2024
Excessive binary privileges in Ivanti Connect Secure which affects versions 22.4R2 through 22.7R2...
High
Unreviewed
CVE-2024-47906
was published
Nov 12, 2024
A privilege escalation issue has been discovered in GitLab EE affecting all versions starting...
Moderate
Unreviewed
CVE-2024-8631
was published
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API