GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,388 advisories
Filter by severity
Windows Container Manager Service Elevation of Privilege Vulnerability This CVE ID is unique from...
High
Unreviewed
CVE-2021-31167
was published
May 24, 2022
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were...
Moderate
Unreviewed
CVE-2021-31907
was published
May 24, 2022
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was...
High
Unreviewed
CVE-2021-31902
was published
May 24, 2022
In multiple managed switches by WAGO in different versions special crafted requests can lead to...
Moderate
Unreviewed
CVE-2021-20996
was published
May 24, 2022
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due...
Moderate
Unreviewed
CVE-2021-20429
was published
May 24, 2022
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions...
High
Unreviewed
CVE-2021-22117
was published
May 24, 2022
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the...
High
Unreviewed
CVE-2017-17677
was published
May 24, 2022
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and...
High
Unreviewed
CVE-2021-29686
was published
May 24, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2021-31475
was published
May 24, 2022
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to...
High
Unreviewed
CVE-2020-28909
was published
May 24, 2022
InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to...
Moderate
Unreviewed
CVE-2021-33586
was published
May 24, 2022
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf...
Moderate
Unreviewed
CVE-2021-23021
was published
May 24, 2022
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets...
Moderate
Unreviewed
CVE-2020-14335
was published
May 24, 2022
Withdrawn Advisory: kubernetes-nmstate Insecure Privilege Management
High
CVE-2020-1742
was published
for
github.com/nmstate/kubernetes-nmstate
(Go)
May 24, 2022
•
withdrawn
Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031...
High
Unreviewed
CVE-2021-0102
was published
May 24, 2022
Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before...
High
Unreviewed
CVE-2021-0077
was published
May 24, 2022
Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before...
High
Unreviewed
CVE-2021-0055
was published
May 24, 2022
Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an...
High
Unreviewed
CVE-2021-0105
was published
May 24, 2022
Brocade SANnav before version 2.1.1 allows an authenticated attacker to list directories, and...
Moderate
Unreviewed
CVE-2020-15385
was published
May 24, 2022
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client...
High
Unreviewed
CVE-2021-23022
was published
May 24, 2022
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify...
Moderate
Unreviewed
CVE-2021-31929
was published
May 24, 2022
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows...
Moderate
Unreviewed
CVE-2021-25393
was published
May 24, 2022
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem...
High
Unreviewed
CVE-2021-27483
was published
May 24, 2022
In archiveStoredConversation of MmsService.java, there is a possible way to archive message...
High
Unreviewed
CVE-2021-0539
was published
May 24, 2022
Moodle command execution vulnerability exists in the default legacy spellchecker plugin
Critical
CVE-2021-21809
was published
for
moodle/moodle
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API