GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,330
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
408 advisories
Filter by severity
In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak...
Moderate
Unreviewed
CVE-2024-43086
was published
Nov 13, 2024
Incorrect default permissions in some Intel(R) Distribution for Python software before version...
Moderate
Unreviewed
CVE-2024-29083
was published
Nov 13, 2024
Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may...
Moderate
Unreviewed
CVE-2024-35201
was published
Nov 13, 2024
Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows...
Moderate
Unreviewed
CVE-2024-25647
was published
Nov 13, 2024
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to...
Moderate
Unreviewed
CVE-2024-34679
was published
Nov 6, 2024
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected...
Moderate
Unreviewed
CVE-2024-46894
was published
Nov 12, 2024
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to...
Moderate
Unreviewed
CVE-2024-47593
was published
Nov 12, 2024
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged...
Moderate
Unreviewed
CVE-2023-23344
was published
Jun 23, 2023
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
Moderate
Unreviewed
CVE-2024-10469
was published
Oct 28, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Moderate
Unreviewed
CVE-2024-20921
was published
Feb 17, 2024
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a...
Moderate
Unreviewed
CVE-2024-26302
was published
Feb 28, 2024
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource...
Moderate
Unreviewed
CVE-2024-34223
was published
May 14, 2024
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
Moderate
CVE-2024-26280
was published
for
apache-airflow
(pip)
Mar 1, 2024
Cilium's CIDR deny policies may not take effect when a more narrow CIDR allow is present
Moderate
CVE-2024-47825
was published
for
github.com/cilium/cilium
(Go)
Oct 21, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-23201
was published
Mar 8, 2024
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to...
Moderate
Unreviewed
CVE-2024-46544
was published
Sep 23, 2024
In multiple locations, there is a possible information leak due to a missing permission check....
Moderate
Unreviewed
CVE-2024-31312
was published
Jul 9, 2024
Phone information disclosure vulnerability
Moderate
CVE-2024-22889
was published
for
Plone
(pip)
Mar 6, 2024
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function...
Moderate
Unreviewed
CVE-2018-14335
was published
May 13, 2022
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis...
Moderate
Unreviewed
CVE-2023-38335
was published
Jul 20, 2023
Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for...
Moderate
Unreviewed
CVE-2023-38334
was published
Jul 20, 2023
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS...
Moderate
Unreviewed
CVE-2023-49721
was published
Feb 15, 2024
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to...
Moderate
Unreviewed
CVE-2024-10183
was published
Oct 22, 2024
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8...
Moderate
Unreviewed
CVE-2024-35287
was published
Oct 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo...
Moderate
Unreviewed
CVE-2024-22301
was published
Jan 24, 2024
ProTip!
Advisories are also available from the
GraphQL API