GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,715
Erlang
34
GitHub Actions
28
Go
2,302
Maven
5,000+
npm
3,946
NuGet
711
pip
3,716
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
632 advisories
Filter by severity
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a...
High
Unreviewed
CVE-2022-33996
was published
Jul 8, 2022
There is an unauthorized service in the system service. Since the component does not have...
High
Unreviewed
CVE-2022-20436
was published
Oct 12, 2022
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2...
High
Unreviewed
CVE-2022-34043
was published
Jun 30, 2022
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants...
High
Unreviewed
CVE-2021-41635
was published
Jun 25, 2022
There is a Unauthorized service in the system service, may cause the system reboot. Since the...
High
Unreviewed
CVE-2022-20435
was published
Oct 12, 2022
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the...
High
Unreviewed
CVE-2022-33023
was published
Jun 30, 2022
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may...
High
Unreviewed
CVE-2022-26344
was published
Aug 19, 2022
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low...
High
Unreviewed
CVE-2022-1833
was published
Jun 22, 2022
A privilege escalation vulnerability exists in the Windows version of installation for Advantech...
High
Unreviewed
CVE-2021-21912
was published
Dec 23, 2021
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read...
High
Unreviewed
CVE-2021-41637
was published
Jun 25, 2022
A permission issue affects users that deployed the shipped version of the Checkmk Debian package....
High
Unreviewed
CVE-2022-33912
was published
Jun 18, 2022
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner...
High
Unreviewed
CVE-2022-20137
was published
Jun 16, 2022
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection...
High
Unreviewed
CVE-2022-32562
was published
Jun 14, 2022
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default...
High
Unreviewed
CVE-2020-10145
was published
May 24, 2022
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious...
High
Unreviewed
CVE-2022-29483
was published
Jun 3, 2022
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts...
High
Unreviewed
CVE-2021-0603
was published
May 24, 2022
A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID...
High
Unreviewed
CVE-2020-13534
was published
May 24, 2022
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
High
Unreviewed
CVE-2022-31500
was published
Jun 3, 2022
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and...
High
Unreviewed
CVE-2020-27568
was published
May 24, 2022
In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest...
High
Unreviewed
CVE-2020-0485
was published
May 24, 2022
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation...
High
Unreviewed
CVE-2021-28098
was published
May 24, 2022
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This...
High
Unreviewed
CVE-2021-0389
was published
May 24, 2022
A mobile phone of ZTE is impacted by improper access control vulnerability. Due to improper...
High
Unreviewed
CVE-2021-21732
was published
May 24, 2022
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify...
High
Unreviewed
CVE-2021-0380
was published
May 24, 2022
In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing...
High
Unreviewed
CVE-2020-0298
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API