GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
48 advisories
Filter by severity
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Duplicate Advisory: Full Table Permissions by Default
High
GHSA-m8pp-qc66-6pgp
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Apache ActiveMQ has an Incorrect Default Permissions vulnerability
High
CVE-2026-49157
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
High
CVE-2026-41712
was published
for
org.springframework.ai:spring-ai-advisors-vector-store
(Maven)
May 12, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability
High
GHSA-387c-qmrw-59qv
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 10, 2026
•
withdrawn
AutoGPT is Vulnerable to RCE via Disabled Block Execution
High
CVE-2026-24780
was published
for
agpt
(pip)
Jan 29, 2026
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
High
CVE-2025-53945
was published
for
chainguard.dev/apko
(Go)
Jul 18, 2025
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
High
CVE-2025-24399
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Jan 22, 2025
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
pgAdmin has Incorrect Default Permissions
High
CVE-2023-1907
was published
for
pgadmin4
(pip)
Jan 9, 2025
Kolide Agent Privilege Escalation (Windows, Versions >= 1.5.3, < 1.12.3)
High
CVE-2024-54131
was published
for
github.com/kolide/launcher
(Go)
Dec 3, 2024
MLflow's excessive directory permissions allow local privilege escalation
High
CVE-2024-27134
was published
for
mlflow
(pip)
Nov 25, 2024
Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
High
CVE-2024-52551
was published
for
org.jenkinsci.plugins:pipeline-model-parent
(Maven)
Nov 13, 2024
Improper Preservation of Permissions in xxl-job
High
CVE-2024-42681
was published
for
com.xuxueli:xxl-job-core
(Maven)
Aug 15, 2024
Kubean vulnerable to cluster-level privilege escalation
High
CVE-2024-41820
was published
for
github.com/kubean-io/kubean
(Go)
Aug 5, 2024
Kubernetes sets incorrect permissions on Windows containers logs
High
CVE-2024-5321
was published
for
k8s.io/kubernetes
(Go)
Jul 18, 2024
langchain_experimental Code Execution via Python REPL access
High
CVE-2024-38459
was published
for
langchain-experimental
(pip)
Jun 16, 2024
Mautic Sensitive Data Exposure due to inadequate user permission settings
High
CVE-2022-25776
was published
for
mautic/core
(Composer)
Apr 12, 2024
SurrealDB: Full Table Permissions by Default
High
CVE-2023-54366
was published
for
surrealdb
(Rust)
Dec 15, 2023
Withdrawn Advisory: Mobile Security Framework (MobSF) Vulnerable to Insecure Permissions
High
CVE-2023-42261
was published
for
mobsf
(pip)
Sep 22, 2023
•
withdrawn
Jenkins temporary plugin file created with insecure permissions
High
CVE-2023-43496
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 20, 2023
ProTip!
Advisories are also available from the
GraphQL API