GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,080 advisories
Filter by severity
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a...
Moderate
Unreviewed
CVE-2024-26302
was published
Feb 28, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Moderate
Unreviewed
CVE-2024-20921
was published
Feb 17, 2024
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource...
Moderate
Unreviewed
CVE-2024-34223
was published
May 14, 2024
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
Low
Unreviewed
CVE-2024-30204
was published
Mar 25, 2024
The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access...
High
Unreviewed
CVE-2024-9191
was published
Nov 2, 2024
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
Moderate
CVE-2024-26280
was published
for
apache-airflow
(pip)
Mar 1, 2024
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Moderate
CVE-2024-47825
was published
for
github.com/cilium/cilium
(Go)
Oct 21, 2024
An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on...
High
Unreviewed
CVE-2023-38291
was published
Apr 22, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-23201
was published
Mar 8, 2024
ntfs3 in the Linux kernel before 6.5.11 allows a physically proximate attacker to read kernel...
High
Unreviewed
CVE-2023-45896
was published
Aug 28, 2024
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to...
Moderate
Unreviewed
CVE-2024-46544
was published
Sep 23, 2024
In multiple locations, there is a possible information leak due to a missing permission check....
Moderate
Unreviewed
CVE-2024-31312
was published
Jul 9, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21002
was published
Apr 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21004
was published
Apr 17, 2024
Phone information disclosure vulnerability
Moderate
CVE-2024-22889
was published
for
Plone
(pip)
Mar 6, 2024
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An...
High
Unreviewed
CVE-2024-44228
was published
Oct 28, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2024-40792
was published
Oct 28, 2024
A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers...
Unknown
Unreviewed
CVE-2024-48572
was published
Oct 30, 2024
pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers...
High
Unreviewed
CVE-2024-6238
was published
Jun 25, 2024
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions...
High
Unreviewed
CVE-2024-34221
was published
May 14, 2024
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function...
Moderate
Unreviewed
CVE-2018-14335
was published
May 13, 2022
Permission management vulnerability in the lock screen module.Successful exploitation of this...
High
Unreviewed
CVE-2023-52362
was published
Feb 18, 2024
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi...
High
Unreviewed
CVE-2024-42028
was published
Oct 28, 2024
An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted...
High
Unreviewed
CVE-2023-31462
was published
Jul 20, 2023
Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow...
High
Unreviewed
CVE-2023-34315
was published
Oct 28, 2024
ProTip!
Advisories are also available from the
GraphQL API