GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,522
Maven
5,000+
npm
4,176
NuGet
741
pip
3,965
Pub
12
RubyGems
947
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,337 advisories
Filter by severity
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1...
Moderate
Unreviewed
CVE-2024-34648
was published
Sep 4, 2024
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7...
Moderate
Unreviewed
CVE-2024-34661
was published
Sep 4, 2024
NNM failed to properly set ACLs on its installation directory, which could allow a low...
High
Unreviewed
CVE-2023-5623
was published
Oct 26, 2023
Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials
Low
GHSA-gmrm-8fx4-66x7
was published
for
org.keycloak:keycloak-core
(Maven)
Jun 18, 2024
•
withdrawn
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www...
Moderate
Unreviewed
CVE-2024-6325
was published
Jul 16, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38222
was published
Sep 12, 2024
Incorrect Default Permissions in Cobbler
High
CVE-2021-45083
was published
for
cobbler
(pip)
Feb 21, 2022
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious...
Critical
Unreviewed
CVE-2020-14521
was published
Feb 12, 2022
Mautic Sensitive Data Exposure due to inadequate user permission settings
High
CVE-2022-25776
was published
for
mautic/core
(Composer)
Apr 12, 2024
Django Incorrect Default Permissions
High
CVE-2020-24583
was published
for
Django
(pip)
Mar 18, 2021
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The...
High
Unreviewed
CVE-2024-8533
was published
Sep 12, 2024
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk®...
Low
Unreviewed
CVE-2024-6326
was published
Jul 16, 2024
JSNAPy allows unprivileged local users to alter files under the directory
High
CVE-2018-0023
was published
for
jsnapy
(pip)
Jul 12, 2018
Incorrect Default Permissions in keyring
High
CVE-2012-5577
was published
for
keyring
(pip)
Mar 11, 2020
Incorrect Default Permissions in keyring
High
CVE-2012-5578
was published
for
keyring
(pip)
Mar 10, 2020
OpenStack Manila Unprivileged users can retrieve, use and manipulate share networks
High
CVE-2020-9543
was published
for
manila
(pip)
May 24, 2022
Duplicate Advisory: Apiman has insufficient checks for read permissions
High
GHSA-54r5-wr8x-x5v3
was published
for
io.apiman:apiman-manager-api-rest-impl
(Maven)
Dec 20, 2022
•
withdrawn
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before...
High
Unreviewed
CVE-2024-9167
was published
Oct 8, 2024
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) ...
Moderate
Unreviewed
CVE-2024-1605
was published
Mar 18, 2024
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts...
Moderate
Unreviewed
CVE-2023-42133
was published
Oct 11, 2024
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper...
Moderate
Unreviewed
CVE-2024-39544
was published
Oct 11, 2024
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby...
Moderate
Unreviewed
CVE-2024-5474
was published
Oct 11, 2024
Permission management vulnerability in the module for disabling Sound Booster. Successful...
Moderate
Unreviewed
CVE-2023-6273
was published
Dec 6, 2023
There exists an insecure default user permission in Google Cloud Migrate to containers from...
Moderate
Unreviewed
CVE-2024-9858
was published
Oct 16, 2024
In multiple locations, there is a possible permission bypass due to a confused deputy. This could...
High
Unreviewed
CVE-2024-40654
was published
Sep 11, 2024
ProTip!
Advisories are also available from the
GraphQL API