GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,232 advisories
Filter by severity
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling...
High
Unreviewed
CVE-2021-4199
was published
Mar 8, 2022
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels...
Moderate
Unreviewed
CVE-2021-3631
was published
Mar 4, 2022
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The...
Moderate
Unreviewed
CVE-2022-26157
was published
Mar 1, 2022
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1...
Moderate
Unreviewed
CVE-2020-27958
was published
Feb 27, 2022
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write...
Moderate
Unreviewed
CVE-2022-0247
was published
Feb 26, 2022
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with...
High
Unreviewed
CVE-2022-24327
was published
Feb 26, 2022
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged...
Moderate
Unreviewed
CVE-2022-25363
was published
Feb 25, 2022
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support...
High
Unreviewed
CVE-2020-25718
was published
Feb 19, 2022
RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This...
High
Unreviewed
CVE-2022-25335
was published
Feb 19, 2022
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and...
Moderate
Unreviewed
CVE-2021-3557
was published
Feb 17, 2022
Kubernetes Unsafe Cacheing
Moderate
CVE-2019-11244
was published
for
k8s.io/client-go
(Go)
Feb 15, 2022
Apache Cassandra vulnerable to Code Injection due to unsafe configuration
Critical
CVE-2021-44521
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 12, 2022
Local privilege escalation due to insecure folder permissions. The following products are...
High
Unreviewed
CVE-2022-0483
was published
Feb 12, 2022
There is an improper security permission configuration vulnerability on ACPU.Successful...
High
Unreviewed
CVE-2021-39992
was published
Feb 11, 2022
Incorrect Permission Assignment for Critical Resource in CRI-O
Moderate
CVE-2022-0532
was published
for
github.com/cri-o/cri-o
(Go)
Feb 11, 2022
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M...
High
Unreviewed
CVE-2021-22284
was published
Feb 10, 2022
Improper privilege handling in Apache Accumulo
High
CVE-2020-17533
was published
for
org.apache.accumulo:accumulo-master
(Maven)
Feb 9, 2022
Incorrect Permission Assignment for Critical Resource in Ansible
Moderate
CVE-2020-1736
was published
for
ansible
(pip)
Feb 9, 2022
Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak
Moderate
CVE-2020-1694
was published
for
org.keycloak:keycloak-parent
(Maven)
Feb 9, 2022
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before...
High
Unreviewed
CVE-2021-46561
was published
Feb 8, 2022
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers...
High
Unreviewed
CVE-2022-0270
was published
Jan 26, 2022
Incorrect Permission Assignment for Critical Resource in OnionShare
Moderate
CVE-2022-21694
was published
for
onionshare-cli
(pip)
Jan 21, 2022
Microweber Incorrect Permission Assignment for Critical Resource vulnerability
Moderate
CVE-2022-0277
was published
for
microweber/microweber
(Composer)
Jan 21, 2022
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable...
Critical
Unreviewed
CVE-2021-22566
was published
Jan 19, 2022
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID...
High
Unreviewed
CVE-2022-23132
was published
Jan 14, 2022
ProTip!
Advisories are also available from the
GraphQL API