GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,232 advisories
Filter by severity
Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24...
High
Unreviewed
CVE-2024-12363
was published
Dec 11, 2024
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated...
High
Unreviewed
CVE-2024-7572
was published
Dec 10, 2024
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local...
High
Unreviewed
CVE-2024-8540
was published
Dec 10, 2024
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated...
High
Unreviewed
CVE-2024-10256
was published
Dec 10, 2024
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v...
Critical
Unreviewed
CVE-2024-41647
was published
Dec 7, 2024
In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices...
Moderate
Unreviewed
CVE-2024-8256
was published
Dec 10, 2024
Incorrect permission assignment in temporary access requests component in Devolutions Remote...
High
Unreviewed
CVE-2024-12149
was published
Dec 4, 2024
Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0...
Moderate
Unreviewed
CVE-2024-12151
was published
Dec 4, 2024
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.8...
Moderate
Unreviewed
CVE-2024-45841
was published
Dec 5, 2024
Vulnerability in the PeopleSoft Enterprise HCM Benefits Administration product of Oracle...
Moderate
Unreviewed
CVE-2024-21063
was published
Apr 17, 2024
stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp...
Moderate
Unreviewed
CVE-2024-54159
was published
Nov 30, 2024
Spring Security's spring-security.xsd file is world writable
Moderate
CVE-2023-34042
was published
for
org.springframework.security:spring-security-config
(Maven)
Feb 6, 2024
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of...
Moderate
Unreviewed
CVE-2024-21703
was published
Nov 27, 2024
A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD)...
Moderate
Unreviewed
CVE-2020-3312
was published
May 24, 2022
Affected devices create coredump files when crashed, storing them with world-readable permission....
Moderate
Unreviewed
CVE-2024-28955
was published
Nov 26, 2024
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS...
Low
Unreviewed
CVE-2024-44575
was published
Sep 11, 2024
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation...
High
Unreviewed
CVE-2024-9244
was published
Nov 23, 2024
Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation...
High
Unreviewed
CVE-2024-9245
was published
Nov 23, 2024
Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-7245
was published
Nov 23, 2024
G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-6871
was published
Nov 23, 2024
An incorrect permission assignment for critical resource vulnerability has been reported to...
High
Unreviewed
CVE-2024-38646
was published
Nov 22, 2024
Local Privilege Escalation in Windows
High
CVE-2023-49797
was published
for
pyinstaller
(pip)
Dec 9, 2023
Improper export of Android application components issue exists in 'ABEMA' App for Android prior...
Low
Unreviewed
CVE-2024-28745
was published
Mar 18, 2024
Kubean vulnerable to cluster-level privilege escalation
High
CVE-2024-41820
was published
for
github.com/kubean-io/kubean
(Go)
Aug 5, 2024
On Windows systems, the Arc configuration files resulted to be world-readable.
This can lead...
Moderate
Unreviewed
CVE-2023-5937
was published
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API