GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
97 advisories
Filter by severity
Koji hub call does not perform correct access checks
Critical
CVE-2018-1002150
was published
for
koji
(pip)
Jul 12, 2018
Incorrect Permission Assignment for Critical Resource in Plone
Critical
CVE-2021-33509
was published
for
Plone
(pip)
Jun 15, 2021
Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase®...
Critical
Unreviewed
CVE-2021-42115
was published
Dec 1, 2021
HashiCorp Vault Incorrect Permission Assignment for Critical Resource
Critical
CVE-2021-43998
was published
for
github.com/hashicorp/vault
(Go)
Dec 2, 2021
File and directory permissions have been corrected to prevent unintended users from modifying or...
Critical
Unreviewed
CVE-2022-22988
was published
Jan 14, 2022
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable...
Critical
Unreviewed
CVE-2021-22566
was published
Jan 19, 2022
Apache Cassandra vulnerable to Code Injection due to unsafe configuration
Critical
CVE-2021-44521
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 12, 2022
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any...
Critical
Unreviewed
CVE-2022-24074
was published
Mar 18, 2022
Struts ParameterInterceptor vulnerability allows remote command execution
Critical
CVE-2011-3923
was published
for
org.apache.struts:struts2-core
(Maven)
Apr 22, 2022
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client...
Critical
Unreviewed
CVE-2012-2087
was published
Apr 23, 2022
Incorrect Permission Assignment for Critical Resource in ShopXO
Critical
CVE-2022-28056
was published
for
shopxo/shopxo
(Composer)
May 3, 2022
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities...
Critical
Unreviewed
CVE-2017-12816
was published
May 13, 2022
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog...
Critical
Unreviewed
CVE-2018-1115
was published
May 13, 2022
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs)...
Critical
Unreviewed
CVE-2017-7471
was published
May 13, 2022
An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on...
Critical
Unreviewed
CVE-2018-11240
was published
May 13, 2022
Mercurial Incorrect Access Control vulnerability
Critical
CVE-2018-1000132
was published
for
mercurial
(pip)
May 13, 2022
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer...
Critical
Unreviewed
CVE-2017-9602
was published
May 13, 2022
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable...
Critical
Unreviewed
CVE-2018-1164
was published
May 13, 2022
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted...
Critical
Unreviewed
CVE-2018-15379
was published
May 13, 2022
Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access....
Critical
Unreviewed
CVE-2017-9626
was published
May 13, 2022
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to...
Critical
Unreviewed
CVE-2017-1000153
was published
May 13, 2022
Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view...
Critical
Unreviewed
CVE-2017-15877
was published
May 13, 2022
The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to...
Critical
Unreviewed
CVE-2017-16638
was published
May 13, 2022
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended...
Critical
Unreviewed
CVE-2017-16885
was published
May 13, 2022
A mechanism to bypass file system access protections in the sandbox using the file system request...
Critical
Unreviewed
CVE-2017-5456
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API