GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,386 advisories
Filter by severity
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro...
Moderate
Unreviewed
CVE-2020-8602
was published
May 24, 2022
OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.
Moderate
Unreviewed
CVE-2020-24716
was published
May 24, 2022
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where...
Moderate
Unreviewed
CVE-2020-5417
was published
May 24, 2022
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode...
Moderate
Unreviewed
CVE-2020-20634
was published
May 24, 2022
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions...
Moderate
Unreviewed
CVE-2020-24394
was published
May 24, 2022
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root...
High
Unreviewed
CVE-2020-24330
was published
May 24, 2022
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root...
High
Unreviewed
CVE-2020-24331
was published
May 24, 2022
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8...
Moderate
Unreviewed
CVE-2020-0559
was published
May 24, 2022
Wowza Streaming Engine through 2019-11-28 has Insecure Permissions.
High
Unreviewed
CVE-2019-19455
was published
May 24, 2022
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
High
Unreviewed
CVE-2020-15871
was published
May 24, 2022
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file...
High
Unreviewed
CVE-2020-9671
was published
May 24, 2022
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag,...
Moderate
Unreviewed
CVE-2020-6267
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5...
Low
Unreviewed
CVE-2020-4414
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not...
Moderate
Unreviewed
CVE-2019-20887
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially...
Moderate
Unreviewed
CVE-2019-20884
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e...
Moderate
Unreviewed
CVE-2019-20879
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only....
Low
Unreviewed
CVE-2019-20883
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a...
Moderate
Unreviewed
CVE-2019-20875
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can...
Moderate
Unreviewed
CVE-2019-20876
was published
May 24, 2022
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non...
Moderate
Unreviewed
CVE-2019-20869
was published
May 24, 2022
Mattermost Server allows System Admin to modify LDAP account names and email addresses
Low
CVE-2016-11077
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
An exposure of sensitive information flaw was found in Ansible Tower before version 3.7.1....
Low
Unreviewed
CVE-2020-10782
was published
May 24, 2022
An access issue was addressed with improved access restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2020-9851
was published
May 24, 2022
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does...
Low
Unreviewed
CVE-2020-13696
was published
May 24, 2022
In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link...
Moderate
Unreviewed
CVE-2020-12848
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API