GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,336 advisories
Filter by severity
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable...
Moderate
Unreviewed
CVE-2021-0428
was published
May 24, 2022
In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing...
High
Unreviewed
CVE-2020-0298
was published
May 24, 2022
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1...
Moderate
Unreviewed
CVE-2020-13270
was published
May 24, 2022
In createInputConsumer of WindowManagerService.java, there is a possible way to block and...
High
Unreviewed
CVE-2020-0475
was published
May 24, 2022
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a...
High
Unreviewed
CVE-2020-0440
was published
May 24, 2022
Incorrect Default Permissions in JetBrains Kotlin
Moderate
CVE-2020-29582
was published
for
org.jetbrains.kotlin:kotlin-stdlib
(Maven)
May 24, 2022
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due...
High
Unreviewed
CVE-2020-0439
was published
May 24, 2022
In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing...
High
Unreviewed
CVE-2020-0299
was published
May 24, 2022
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to...
High
Unreviewed
CVE-2020-0227
was published
May 24, 2022
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to...
Moderate
Unreviewed
CVE-2020-4270
was published
May 24, 2022
Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers...
High
Unreviewed
CVE-2022-28999
was published
May 24, 2022
Permission control vulnerability in the network module. Successful exploitation of this...
High
Unreviewed
CVE-2022-37006
was published
Aug 11, 2022
A improper permission configuration vulnerability in Xiaomi Content Center APP. This...
Moderate
Unreviewed
CVE-2020-14117
was published
Apr 22, 2022
Incorrect Default Permissions in Apache Commons FileUpload
Low
CVE-2013-0248
was published
for
commons-fileupload:commons-fileupload
(Maven)
May 5, 2022
A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175...
Moderate
Unreviewed
CVE-2021-3722
was published
Apr 23, 2022
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an...
High
Unreviewed
CVE-2022-4020
was published
Nov 28, 2022
Incorrect Default Permissions in CRI-O
Moderate
CVE-2022-27652
was published
for
github.com/cri-o/cri-o
(Go)
Apr 22, 2022
A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager...
High
Unreviewed
CVE-2022-20732
was published
Apr 22, 2022
Access to Unix domain socket can lead to privileges escalation in Cilium
High
CVE-2022-29178
was published
for
github.com/cilium/cilium
(Go)
May 24, 2022
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking...
Moderate
Unreviewed
CVE-2011-1762
was published
Apr 19, 2022
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the...
High
Unreviewed
CVE-2022-29547
was published
Apr 22, 2022
In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the...
High
Unreviewed
CVE-2021-39794
was published
Apr 13, 2022
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local...
Moderate
Unreviewed
CVE-2022-27840
was published
Apr 12, 2022
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1...
Moderate
Unreviewed
CVE-2022-27960
was published
Apr 11, 2022
Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions...
Moderate
Unreviewed
CVE-2022-26855
was published
Apr 9, 2022
ProTip!
Advisories are also available from the
GraphQL API