GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
759 advisories
Filter by severity
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in...
High
Unreviewed
CVE-2026-29126
was published
Mar 5, 2026
iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged...
High
Unreviewed
CVE-2026-2637
was published
Mar 3, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26102
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26096
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26101
was published
Feb 20, 2026
Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File...
High
Unreviewed
CVE-2026-26095
was published
Feb 20, 2026
IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system...
High
Unreviewed
CVE-2025-33088
was published
Feb 18, 2026
Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system...
High
Unreviewed
CVE-2026-23648
was published
Feb 17, 2026
NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to...
High
Unreviewed
CVE-2019-25343
was published
Feb 12, 2026
Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local...
High
Unreviewed
CVE-2019-25344
was published
Feb 12, 2026
Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to...
High
Unreviewed
CVE-2025-61969
was published
Feb 11, 2026
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated...
High
Unreviewed
CVE-2020-36938
was published
Jan 27, 2026
Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2026-0775
was published
for
npm
(npm)
Jan 23, 2026
•
withdrawn
IBM Licensing Operator incorrectly assigns privileges to security critical files which could...
High
Unreviewed
CVE-2025-12985
was published
Jan 20, 2026
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that...
High
Unreviewed
CVE-2021-47756
was published
Jan 16, 2026
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers...
High
Unreviewed
CVE-2022-50931
was published
Jan 14, 2026
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to...
High
Unreviewed
CVE-2025-14979
was published
Jan 6, 2026
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that...
High
Unreviewed
CVE-2020-36916
was published
Jan 6, 2026
Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that...
High
Unreviewed
CVE-2021-47742
was published
Dec 31, 2025
An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The...
High
Unreviewed
CVE-2025-64699
was published
Dec 31, 2025
inMusic Brands Engine DJ 4.3.0 suffers from Insecure Permissions due to exposed HTTP service in...
High
Unreviewed
CVE-2025-66723
was published
Dec 30, 2025
Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows...
High
Unreviewed
CVE-2019-25245
was published
Dec 24, 2025
VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2025-13703
was published
Dec 24, 2025
Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to...
High
Unreviewed
CVE-2022-50690
was published
Dec 23, 2025
AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate...
High
Unreviewed
CVE-2023-53949
was published
Dec 19, 2025
ProTip!
Advisories are also available from the
GraphQL API