GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
611 advisories
Filter by severity
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA...
High
Unreviewed
CVE-2021-22669
was published
May 24, 2022
SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running...
High
Unreviewed
CVE-2020-15593
was published
May 24, 2022
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission...
High
Unreviewed
CVE-2022-20329
was published
Aug 13, 2022
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC)...
High
Unreviewed
CVE-2020-0951
was published
May 24, 2022
Local privilege escalation due to insecure folder permissions. The following products are...
High
Unreviewed
CVE-2022-44733
was published
Nov 8, 2022
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu,...
High
Unreviewed
CVE-2019-3467
was published
May 24, 2022
CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
High
CVE-2022-2995
was published
for
github.com/cri-o/cri-o
(Go)
Sep 20, 2022
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions). The affected...
High
Unreviewed
CVE-2022-43517
was published
Dec 13, 2022
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x...
High
Unreviewed
CVE-2022-29263
was published
May 6, 2022
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient...
High
Unreviewed
CVE-2021-44167
was published
May 12, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2018-3974
was published
May 13, 2022
The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for...
High
Unreviewed
CVE-2018-5546
was published
May 13, 2022
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control...
High
Unreviewed
CVE-2018-1267
was published
May 13, 2022
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non...
High
Unreviewed
CVE-2017-2290
was published
May 13, 2022
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary...
High
Unreviewed
CVE-2017-8665
was published
May 13, 2022
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary...
High
Unreviewed
CVE-2017-16928
was published
May 13, 2022
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control...
High
Unreviewed
CVE-2018-12922
was published
May 13, 2022
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to...
High
Unreviewed
CVE-2017-16945
was published
May 13, 2022
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory,...
High
Unreviewed
CVE-2017-11652
was published
May 13, 2022
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect,...
High
Unreviewed
CVE-2018-17776
was published
May 13, 2022
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which...
High
Unreviewed
CVE-2017-11653
was published
May 13, 2022
IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4)...
High
Unreviewed
CVE-2018-1386
was published
May 13, 2022
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company...
High
Unreviewed
CVE-2018-13411
was published
May 13, 2022
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10...
High
Unreviewed
CVE-2018-13412
was published
May 13, 2022
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2...
High
Unreviewed
CVE-2017-13779
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API