GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,000 advisories
Filter by severity
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure...
High
Unreviewed
CVE-2023-26077
was published
Jul 24, 2023
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS...
Moderate
Unreviewed
CVE-2023-49721
was published
Feb 15, 2024
Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0...
High
Unreviewed
CVE-2023-41231
was published
Oct 24, 2024
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from...
Critical
Unreviewed
CVE-2023-33745
was published
Jul 27, 2023
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6,...
High
Unreviewed
CVE-2023-38410
was published
Jul 27, 2023
netaddr before 1.5.3 and 2.0.4 has Incorrect Default Permissions
Critical
CVE-2019-17383
was published
for
netaddr
(RubyGems)
Oct 14, 2019
Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901...
High
Unreviewed
CVE-2023-40154
was published
Oct 23, 2024
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions...
High
Unreviewed
CVE-2024-9947
was published
Oct 23, 2024
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers...
High
Unreviewed
CVE-2024-7587
was published
Oct 23, 2024
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to...
Moderate
Unreviewed
CVE-2024-10183
was published
Oct 22, 2024
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8...
Moderate
Unreviewed
CVE-2024-35287
was published
Oct 21, 2024
Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a...
High
Unreviewed
CVE-2023-38960
was published
Feb 14, 2024
rtslib-fb weak permissions for /etc/target/saveconfig.json file
High
CVE-2020-14019
was published
for
rtslib-fb
(pip)
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo...
Moderate
Unreviewed
CVE-2024-22301
was published
Jan 24, 2024
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A...
Moderate
Unreviewed
CVE-2024-47240
was published
Oct 18, 2024
In Telerik Test Studio versions prior to
v2023.3.1330, a privilege elevation vulnerability has...
High
Unreviewed
CVE-2024-0833
was published
Jan 31, 2024
In the Linux kernel, the following vulnerability has been resolved:
selinux,smack: don't bypass...
Moderate
Unreviewed
CVE-2024-46695
was published
Sep 13, 2024
Local privilege escalation due to insecure folder permissions. The following products are...
High
Unreviewed
CVE-2024-49389
was published
Oct 17, 2024
In multiple locations, there is a possible permission bypass due to a confused deputy. This could...
High
Unreviewed
CVE-2024-40654
was published
Sep 11, 2024
There exists an insecure default user permission in Google Cloud Migrate to containers from...
Moderate
Unreviewed
CVE-2024-9858
was published
Oct 16, 2024
Permission management vulnerability in the module for disabling Sound Booster. Successful...
Moderate
Unreviewed
CVE-2023-6273
was published
Dec 6, 2023
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby...
Moderate
Unreviewed
CVE-2024-5474
was published
Oct 11, 2024
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper...
Moderate
Unreviewed
CVE-2024-39544
was published
Oct 11, 2024
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts...
Moderate
Unreviewed
CVE-2023-42133
was published
Oct 11, 2024
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) ...
Moderate
Unreviewed
CVE-2024-1605
was published
Mar 18, 2024
ProTip!
Advisories are also available from the
GraphQL API