GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
3,917 advisories
Filter by severity
The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
Critical
Unreviewed
CVE-2025-13559
was published
Nov 25, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
An Improper Privilege Management vulnerability [CWE-269] in Fortinet FortiOS 7.6.0 through 7.6.3,...
Low
Unreviewed
CVE-2025-54821
was published
Nov 18, 2025
A missing validation process exists in Serv U when abused, could give a malicious actor with...
Critical
Unreviewed
CVE-2025-40548
was published
Nov 18, 2025
LXD vulnerable to a local privilege escalation through custom storage volumes
High
GHSA-3g2j-vm47-x4mj
was published
for
github.com/canonical/lxd
(Go)
Nov 13, 2025
A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute...
Moderate
Unreviewed
CVE-2025-20346
was published
Nov 13, 2025
Incus vulnerable to local privilege escalation through custom storage volumes
High
CVE-2025-64507
was published
for
github.com/lxc/incus
(Go)
Nov 13, 2025
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is...
High
Unreviewed
CVE-2025-11923
was published
Nov 13, 2025
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to...
High
Unreviewed
CVE-2025-59514
was published
Nov 11, 2025
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001...
Moderate
Unreviewed
CVE-2025-24863
was published
Nov 11, 2025
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001...
High
Unreviewed
CVE-2025-24838
was published
Nov 11, 2025
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001...
Low
Unreviewed
CVE-2025-24307
was published
Nov 11, 2025
The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up...
High
Unreviewed
CVE-2025-11168
was published
Nov 11, 2025
The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress...
Critical
Unreviewed
CVE-2025-11457
was published
Nov 11, 2025
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed...
High
Unreviewed
CVE-2025-12726
was published
Nov 10, 2025
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC...
High
Unreviewed
CVE-2025-12405
was published
Nov 10, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025.3.5.0 and...
High
Unreviewed
CVE-2025-12485
was published
Nov 6, 2025
Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with...
Critical
Unreviewed
CVE-2025-46364
was published
Nov 5, 2025
The service employed by Everything, running as SYSTEM, communicates with the lower privileged...
High
Unreviewed
CVE-2025-12683
was published
Nov 4, 2025
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an...
Critical
Unreviewed
CVE-2024-13997
was published
Nov 4, 2025
The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to,...
Critical
Unreviewed
CVE-2025-8900
was published
Nov 3, 2025
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor...
Critical
Unreviewed
CVE-2025-8489
was published
Oct 31, 2025
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if...
High
Unreviewed
CVE-2025-48982
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System...
Critical
Unreviewed
CVE-2024-14009
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API