GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,783
NuGet
683
pip
3,463
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,236 advisories
Filter by severity
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an...
Moderate
Unreviewed
CVE-2019-0111
was published
May 13, 2022
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an...
Moderate
Unreviewed
CVE-2019-0108
was published
May 13, 2022
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS...
High
Unreviewed
CVE-2018-8411
was published
May 13, 2022
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which...
High
Unreviewed
CVE-2018-6261
was published
May 13, 2022
A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak...
High
Unreviewed
CVE-2018-5313
was published
May 13, 2022
A permissions issue existed in which execute permission was incorrectly granted. This issue was...
Moderate
Unreviewed
CVE-2018-4178
was published
May 13, 2022
The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are...
High
Unreviewed
CVE-2018-20798
was published
May 13, 2022
Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was...
High
Unreviewed
CVE-2018-20145
was published
May 13, 2022
The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS...
Moderate
Unreviewed
CVE-2018-18812
was published
May 13, 2022
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation...
Moderate
Unreviewed
CVE-2018-18495
was published
May 13, 2022
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04...
High
Unreviewed
CVE-2018-18561
was published
May 13, 2022
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a...
High
Unreviewed
CVE-2018-18331
was published
May 13, 2022
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to...
High
Unreviewed
CVE-2018-18332
was published
May 13, 2022
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure...
High
Unreviewed
CVE-2018-17872
was published
May 13, 2022
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by...
Moderate
Unreviewed
CVE-2018-1787
was published
May 13, 2022
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with...
High
Unreviewed
CVE-2018-17873
was published
May 13, 2022
Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a...
Moderate
Unreviewed
CVE-2018-16087
was published
May 13, 2022
Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
High
Unreviewed
CVE-2018-15835
was published
May 13, 2022
AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files...
Moderate
Unreviewed
CVE-2018-15809
was published
May 13, 2022
Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file...
Moderate
Unreviewed
CVE-2018-15768
was published
May 13, 2022
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H...
High
Unreviewed
CVE-2018-14987
was published
May 13, 2022
Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain...
High
Unreviewed
CVE-2018-11334
was published
May 13, 2022
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on...
Critical
Unreviewed
CVE-2018-11240
was published
May 13, 2022
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure...
Moderate
Unreviewed
CVE-2018-11002
was published
May 13, 2022
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to...
High
Unreviewed
CVE-2017-16757
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API