GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,383 advisories
Filter by severity
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via...
High
Unreviewed
CVE-2023-31874
was published
May 29, 2023
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local...
High
Unreviewed
CVE-2023-31748
was published
May 24, 2023
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll...
Moderate
Unreviewed
CVE-2023-33251
was published
May 21, 2023
The window management module lacks permission verification.Successful exploitation of this...
High
Unreviewed
CVE-2023-1692
was published
May 20, 2023
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation...
High
Unreviewed
CVE-2023-31871
was published
May 18, 2023
Jenkins File Parameter Plugin arbitrary file write vulnerability
High
CVE-2023-32986
was published
for
io.jenkins.plugins:file-parameters
(Maven)
May 16, 2023
Jenkins Azure VM Agents Plugin missing permission checks
Moderate
CVE-2023-32990
was published
for
org.jenkins-ci.plugins:azure-vm-agents
(Maven)
May 16, 2023
Jenkins SAML Single Sign On(SSO) Plugin missing permission checks
High
CVE-2023-32992
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
May 16, 2023
Jenkins Tag Profiler Plugin missing permission check
Moderate
CVE-2023-33004
was published
for
org.jenkins-ci.plugins:tag-profiler
(Maven)
May 16, 2023
Jenkins Email Extension Plugin missing permission check
Moderate
CVE-2023-32979
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
May 16, 2023
Planet's secret file is created with excessive permissions
High
CVE-2023-32303
was published
for
planet
(pip)
May 12, 2023
IBM API Connect V10 could allow an authenticated user to perform actions that they should not...
High
Unreviewed
CVE-2023-28522
was published
May 12, 2023
Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged ...
Moderate
Unreviewed
CVE-2023-31445
was published
May 11, 2023
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before...
High
Unreviewed
CVE-2022-38103
was published
May 10, 2023
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows...
Moderate
Unreviewed
CVE-2022-41771
was published
May 10, 2023
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may...
High
Unreviewed
CVE-2022-46656
was published
May 10, 2023
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0...
High
Unreviewed
CVE-2022-41658
was published
May 10, 2023
Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows...
High
Unreviewed
CVE-2022-41699
was published
May 10, 2023
An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem...
High
Unreviewed
CVE-2023-29092
was published
May 9, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15...
Moderate
Unreviewed
CVE-2023-2478
was published
May 8, 2023
Dell Command Monitor, versions 10.9 and prior, contains an improper folder permission...
High
Unreviewed
CVE-2023-28068
was published
May 5, 2023
Apache Ranger Hive Plugin missing permissions check
High
CVE-2021-40331
was published
for
org.apache.ranger:ranger-hive-plugin
(Maven)
May 5, 2023
Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows...
High
Unreviewed
CVE-2023-30399
was published
May 4, 2023
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute...
High
Unreviewed
CVE-2023-25438
was published
May 4, 2023
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on...
Critical
Unreviewed
CVE-2023-0834
was published
Apr 28, 2023
ProTip!
Advisories are also available from the
GraphQL API