GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
Moderate
Unreviewed
CVE-2024-0137
was published
Jan 28, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
High
Unreviewed
CVE-2024-0135
was published
Jan 28, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
High
Unreviewed
CVE-2024-0136
was published
Jan 28, 2025
A user with advanced report application access rights can perform actions for which they are not...
High
Unreviewed
CVE-2024-47520
was published
Jan 11, 2025
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users...
Moderate
Unreviewed
CVE-2024-8118
was published
Sep 26, 2024
The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRD
Moderate
CVE-2024-43803
was published
for
github.com/metal3-io/baremetal-operator
(Go)
Sep 3, 2024
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2024-20285
was published
Aug 28, 2024
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to...
High
Unreviewed
CVE-2024-6323
was published
Jun 27, 2024
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component...
Critical
Unreviewed
CVE-2024-33768
was published
May 1, 2024
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe)...
Moderate
Unreviewed
CVE-2024-30388
was published
Apr 12, 2024
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files...
High
Unreviewed
CVE-2023-1305
was published
Jul 6, 2023
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component...
Moderate
Unreviewed
CVE-2023-29580
was published
Apr 12, 2023
Class Loading Vulnerability in Artemis
High
GHSA-227w-wv4j-67h4
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 9, 2022
ProTip!
Advisories are also available from the
GraphQL API