GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
36 advisories
Filter by severity
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products...
High
Unreviewed
CVE-2025-54518
was published
May 15, 2026
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace...
High
Unreviewed
CVE-2026-78122
was published
Aug 23, 2026
A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows...
High
Unreviewed
CVE-2026-40145
was published
Aug 17, 2026
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized...
High
Unreviewed
CVE-2026-62721
was published
Aug 11, 2026
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows...
High
Unreviewed
CVE-2026-56155
was published
Jul 14, 2026
Insufficient granularity of access control in Windows Event Logging Service allows an authorized...
High
Unreviewed
CVE-2026-50502
was published
Jul 14, 2026
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an...
High
Unreviewed
CVE-2026-50405
was published
Jul 14, 2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-55006
was published
Jul 14, 2026
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to...
High
Unreviewed
CVE-2026-48581
was published
Jul 14, 2026
Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist...
High
Unreviewed
CVE-2025-35998
was published
Feb 10, 2026
Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker...
High
Unreviewed
CVE-2021-46747
was published
Jun 1, 2026
Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary...
High
Unreviewed
CVE-2024-21962
was published
May 15, 2026
Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized...
High
Unreviewed
CVE-2026-40365
was published
May 12, 2026
Insufficient granularity of access control in Microsoft Office Click-To-Run allows an authorized...
High
Unreviewed
CVE-2026-35436
was published
May 12, 2026
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to...
High
Unreviewed
CVE-2026-33825
was published
Apr 14, 2026
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability...
High
Unreviewed
CVE-2024-4147
was published
Feb 2, 2026
Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable...
High
Unreviewed
CVE-2025-22839
was published
Aug 12, 2025
Improper input validation in the system management mode (SMM) could allow a privileged attacker...
High
Unreviewed
CVE-2024-21947
was published
Sep 6, 2025
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM,...
High
Unreviewed
CVE-2023-31342
was published
Feb 12, 2025
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM,...
High
Unreviewed
CVE-2023-31343
was published
Feb 12, 2025
A vulnerability has been identified in the Now Platform that could result in data being inferred...
High
Unreviewed
CVE-2025-3648
was published
Jul 8, 2025
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
High
Unreviewed
CVE-2024-33058
was published
Apr 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0...
High
Unreviewed
CVE-2025-29987
was published
Apr 3, 2025
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and...
High
Unreviewed
CVE-2025-20111
was published
Feb 26, 2025
ProTip!
Advisories are also available from the
GraphQL API