GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
470 advisories
Filter by severity
Phone information disclosure vulnerability
Moderate
CVE-2024-22889
was published
for
Plone
(pip)
Mar 6, 2024
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function...
Moderate
Unreviewed
CVE-2018-14335
was published
May 13, 2022
Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis...
Moderate
Unreviewed
CVE-2023-38335
was published
Jul 20, 2023
Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for...
Moderate
Unreviewed
CVE-2023-38334
was published
Jul 20, 2023
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS...
Moderate
Unreviewed
CVE-2023-49721
was published
Feb 15, 2024
A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to...
Moderate
Unreviewed
CVE-2024-10183
was published
Oct 22, 2024
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8...
Moderate
Unreviewed
CVE-2024-35287
was published
Oct 21, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo...
Moderate
Unreviewed
CVE-2024-22301
was published
Jan 24, 2024
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A...
Moderate
Unreviewed
CVE-2024-47240
was published
Oct 18, 2024
In the Linux kernel, the following vulnerability has been resolved:
selinux,smack: don't bypass...
Moderate
Unreviewed
CVE-2024-46695
was published
Sep 13, 2024
There exists an insecure default user permission in Google Cloud Migrate to containers from...
Moderate
Unreviewed
CVE-2024-9858
was published
Oct 16, 2024
Permission management vulnerability in the module for disabling Sound Booster. Successful...
Moderate
Unreviewed
CVE-2023-6273
was published
Dec 6, 2023
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby...
Moderate
Unreviewed
CVE-2024-5474
was published
Oct 11, 2024
An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper...
Moderate
Unreviewed
CVE-2024-39544
was published
Oct 11, 2024
PAX Android based POS devices allow for escalation of privilege via improperly configured scripts...
Moderate
Unreviewed
CVE-2023-42133
was published
Oct 11, 2024
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) ...
Moderate
Unreviewed
CVE-2024-1605
was published
Mar 18, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38222
was published
Sep 12, 2024
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www...
Moderate
Unreviewed
CVE-2024-6325
was published
Jul 16, 2024
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7...
Moderate
Unreviewed
CVE-2024-34661
was published
Sep 4, 2024
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1...
Moderate
Unreviewed
CVE-2024-34648
was published
Sep 4, 2024
Sensitive information disclosure due to insecure folder permissions. The following products are...
Moderate
Unreviewed
CVE-2024-34018
was published
Aug 29, 2024
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is...
Moderate
Unreviewed
CVE-2023-6302
was published
Nov 27, 2023
request_store has Incorrect Default Permissions
Moderate
CVE-2024-43791
was published
for
request_store
(RubyGems)
Aug 23, 2024
Incorrect default permissions for some Intel(R) Connectivity Performance Suite software...
Moderate
Unreviewed
CVE-2023-43747
was published
Aug 14, 2024
Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software...
Moderate
Unreviewed
CVE-2024-22378
was published
Aug 14, 2024
ProTip!
Advisories are also available from the
GraphQL API