GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,336 advisories
Filter by severity
A local attacker with low privileges on the Windows system where the
software is installed can...
Moderate
Unreviewed
CVE-2025-53947
was published
Sep 18, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions
Low
CVE-2025-59349
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Permission management vulnerability in the lock screen module
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2024-58046
was published
Mar 4, 2025
Vulnerability of improper access permission in the process management module
Impact: Successful...
Moderate
Unreviewed
CVE-2025-27521
was published
Mar 4, 2025
Vulnerability of improper access permission in the HDC module
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2024-58050
was published
Mar 4, 2025
Permission control vulnerability in the contacts module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2025-46586
was published
May 6, 2025
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability....
High
Unreviewed
CVE-2025-57625
was published
Sep 16, 2025
Certain files with overly permissive permissions were identified in the out-of-support Control-M...
Moderate
Unreviewed
CVE-2025-55111
was published
Sep 16, 2025
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s)...
High
Unreviewed
CVE-2025-43725
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect...
High
Unreviewed
CVE-2025-43887
was published
Sep 10, 2025
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that,...
High
Unreviewed
CVE-2025-10231
was published
Sep 10, 2025
The AOD module has a vulnerability in permission assignment. Successful exploitation of this...
Critical
Unreviewed
CVE-2022-37003
was published
Aug 11, 2022
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input...
Moderate
Unreviewed
CVE-2025-22425
was published
Sep 4, 2025
Apache DolphinScheduler Incorrect Default Permissions Vulnerability
Low
CVE-2024-43166
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 3, 2025
Multiple i-フィルター products contain an issue with incorrect default permissions. If this...
High
Unreviewed
CVE-2025-57846
was published
Aug 27, 2025
The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-9190
was published
Aug 26, 2025
The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-53813
was published
Aug 26, 2025
The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local...
Moderate
Unreviewed
CVE-2025-53811
was published
Aug 26, 2025
MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and...
Moderate
Unreviewed
CVE-2025-8672
was published
Aug 11, 2025
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which...
High
Unreviewed
CVE-2022-32743
was published
Sep 2, 2022
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local...
High
Unreviewed
CVE-2025-8098
was published
Aug 18, 2025
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install...
High
Unreviewed
CVE-2022-29376
was published
May 24, 2022
A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror...
High
Unreviewed
CVE-2025-3528
was published
May 9, 2025
Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may...
Moderate
Unreviewed
CVE-2025-27559
was published
Aug 12, 2025
Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may...
Moderate
Unreviewed
CVE-2025-20087
was published
Aug 12, 2025
ProTip!
Advisories are also available from the
GraphQL API