GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
Moderate
CVE-2025-48938
was published
for
github.com/cli/go-gh/v2
(Go)
May 30, 2025
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode,...
Moderate
Unreviewed
CVE-2025-1118
was published
Feb 19, 2025
Open Cluster Management vulnerable to Trust Boundary Violation
High
CVE-2024-9779
was published
for
open-cluster-management.io/ocm
(Go)
Dec 18, 2024
Visual Studio Code Python Extension Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49050
was published
Nov 12, 2024
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an...
Moderate
Unreviewed
CVE-2024-20265
was published
Mar 27, 2024
kubevirt-csi: PersistentVolume allows access to HCP's root node
High
CVE-2024-1725
was published
for
github.com/kubevirt/csi-driver
(Go)
Mar 7, 2024
Sandbox escape in Artemis Java Test Sandbox
High
CVE-2024-23682
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which...
High
Unreviewed
CVE-2023-0627
was published
Sep 25, 2023
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If...
High
Unreviewed
CVE-2023-28597
was published
Jul 6, 2023
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are...
Moderate
Unreviewed
CVE-2022-20826
was published
Nov 16, 2022
Class Loading Vulnerability in Artemis
High
GHSA-227w-wv4j-67h4
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 9, 2022
Context isolation bypass via contextBridge in Electron
High
CVE-2020-4077
was published
for
electron
(npm)
Jul 7, 2020
Context isolation bypass via leaked cross-context objects in Electron
High
CVE-2020-4076
was published
for
electron
(npm)
Jul 7, 2020
Context isolation bypass via Promise in Electron
Low
CVE-2020-15096
was published
for
electron
(npm)
Jul 7, 2020
ProTip!
Advisories are also available from the
GraphQL API