GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,336 advisories
Filter by severity
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation...
High
Unreviewed
CVE-2024-21939
was published
Nov 12, 2024
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could...
High
Unreviewed
CVE-2024-21946
was published
Nov 12, 2024
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected...
Moderate
Unreviewed
CVE-2024-46894
was published
Nov 12, 2024
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to...
Moderate
Unreviewed
CVE-2024-47593
was published
Nov 12, 2024
Moodle has insufficient access control
Low
CVE-2024-43430
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func...
Critical
Unreviewed
CVE-2023-27195
was published
Nov 8, 2024
The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any...
High
Unreviewed
CVE-2024-36063
was published
Nov 8, 2024
An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic...
High
Unreviewed
CVE-2020-11921
was published
Nov 7, 2024
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the...
High
Unreviewed
CVE-2019-20458
was published
Nov 7, 2024
An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface...
Critical
Unreviewed
CVE-2019-20457
was published
Nov 7, 2024
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to...
Moderate
Unreviewed
CVE-2024-34679
was published
Nov 6, 2024
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access...
High
Unreviewed
CVE-2024-9191
was published
Nov 2, 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb...
Critical
Unreviewed
CVE-2024-51378
was published
Oct 30, 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows...
Critical
Unreviewed
CVE-2024-51567
was published
Oct 30, 2024
A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers...
Moderate
Unreviewed
CVE-2024-48572
was published
Oct 30, 2024
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An...
High
Unreviewed
CVE-2024-44228
was published
Oct 28, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2024-40792
was published
Oct 28, 2024
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
Moderate
Unreviewed
CVE-2024-10469
was published
Oct 28, 2024
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi...
High
Unreviewed
CVE-2024-42028
was published
Oct 28, 2024
Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow...
High
Unreviewed
CVE-2023-34315
was published
Oct 28, 2024
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request...
Critical
Unreviewed
CVE-2022-30355
was published
Oct 25, 2024
there is a possible privilege escalation due to an insecure default value. This could lead to...
High
Unreviewed
CVE-2024-47016
was published
Oct 25, 2024
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to...
High
Unreviewed
CVE-2024-47013
was published
Oct 25, 2024
ProTip!
Advisories are also available from the
GraphQL API