GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
594 advisories
Filter by severity
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
High
Unreviewed
CVE-2022-26281
was published
Apr 6, 2022
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute...
High
Unreviewed
CVE-2022-26982
was published
Apr 6, 2022
The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow...
High
Unreviewed
CVE-2022-24125
was published
Mar 21, 2022
A Improper Privilege Management vulnerability in the sudoers configuration in cscreen of openSUSE...
High
Unreviewed
CVE-2022-21946
was published
Mar 17, 2022
'Root Service' service implemented in the following Yokogawa Electric products creates some named...
High
Unreviewed
CVE-2022-22148
was published
Mar 12, 2022
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU...
High
Unreviewed
CVE-2022-21819
was published
Mar 12, 2022
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the "...
High
Unreviewed
CVE-2021-42855
was published
Mar 11, 2022
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling...
High
Unreviewed
CVE-2021-4199
was published
Mar 8, 2022
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with...
High
Unreviewed
CVE-2022-24327
was published
Feb 26, 2022
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support...
High
Unreviewed
CVE-2020-25718
was published
Feb 19, 2022
RigoBlock Dragos through 2022-02-17 lacks the onlyOwner modifier for setMultipleAllowances. This...
High
Unreviewed
CVE-2022-25335
was published
Feb 19, 2022
Local privilege escalation due to insecure folder permissions. The following products are...
High
Unreviewed
CVE-2022-0483
was published
Feb 12, 2022
There is an improper security permission configuration vulnerability on ACPU.Successful...
High
Unreviewed
CVE-2021-39992
was published
Feb 11, 2022
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M...
High
Unreviewed
CVE-2021-22284
was published
Feb 10, 2022
Improper privilege handling in Apache Accumulo
High
CVE-2020-17533
was published
for
org.apache.accumulo:accumulo-master
(Maven)
Feb 9, 2022
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before...
High
Unreviewed
CVE-2021-46561
was published
Feb 8, 2022
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers...
High
Unreviewed
CVE-2022-0270
was published
Jan 26, 2022
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID...
High
Unreviewed
CVE-2022-23132
was published
Jan 14, 2022
An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges,...
High
Unreviewed
CVE-2021-42562
was published
Jan 13, 2022
ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default...
High
Unreviewed
CVE-2021-23244
was published
Dec 28, 2021
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition...
High
Unreviewed
CVE-2021-20874
was published
Dec 25, 2021
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited...
High
Unreviewed
CVE-2021-27445
was published
Dec 22, 2021
Insecure permissions on user namespace / fakeroot temporary rootfs in Singularity
High
CVE-2020-25039
was published
for
github.com/sylabs/singularity
(Go)
Dec 20, 2021
Incorrect Permission Assignment for Critical Resource in Singularity
High
CVE-2019-11328
was published
for
github.com/sylabs/singularity
(Go)
Dec 20, 2021
ProTip!
Advisories are also available from the
GraphQL API