GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
95 advisories
Filter by severity
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client...
Critical
Unreviewed
CVE-2012-2087
was published
Apr 23, 2022
Kentico 11 through 12 lets attackers upload and explore files without authentication via the...
Critical
Unreviewed
CVE-2019-12102
was published
May 24, 2022
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform...
Critical
Unreviewed
CVE-2024-21915
was published
Feb 16, 2024
Request to LDAP is sent before user permissions are checked.
Critical
Unreviewed
CVE-2023-32723
was published
Oct 12, 2023
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on...
Critical
Unreviewed
CVE-2023-6593
was published
Dec 12, 2023
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the...
Critical
Unreviewed
CVE-2023-46141
was published
Dec 14, 2023
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG,...
Critical
Unreviewed
CVE-2023-0757
was published
Dec 14, 2023
NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability
Critical
Unreviewed
CVE-2023-40302
was published
Dec 7, 2023
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a...
Critical
Unreviewed
CVE-2023-49946
was published
Dec 3, 2023
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
Critical
Unreviewed
CVE-2023-42489
was published
Oct 25, 2023
File and directory permissions have been corrected to prevent unintended users from modifying or...
Critical
Unreviewed
CVE-2022-22988
was published
Jan 14, 2022
Cobbler Improper Validation of Security Tokens
Critical
CVE-2018-1000226
was published
for
cobbler
(pip)
May 13, 2022
Struts ParameterInterceptor vulnerability allows remote command execution
Critical
CVE-2011-3923
was published
for
org.apache.struts:struts2-core
(Maven)
Apr 22, 2022
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any...
Critical
Unreviewed
CVE-2022-24074
was published
Mar 18, 2022
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2023-24205
was published
Feb 24, 2023
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs)...
Critical
Unreviewed
CVE-2017-7471
was published
May 13, 2022
Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included...
Critical
Unreviewed
CVE-2022-28802
was published
Sep 22, 2022
The AMD EPYC Server processor chips have insufficient access control for protected memory regions...
Critical
Unreviewed
CVE-2018-8933
was published
May 13, 2022
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure...
Critical
Unreviewed
CVE-2018-8932
was published
May 13, 2022
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for...
Critical
Unreviewed
CVE-2018-8931
was published
May 13, 2022
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is...
Critical
Unreviewed
CVE-2018-15681
was published
May 13, 2022
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS...
Critical
Unreviewed
CVE-2018-14982
was published
May 13, 2022
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI...
Critical
Unreviewed
CVE-2018-14981
was published
May 13, 2022
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
Critical
Unreviewed
CVE-2018-15509
was published
May 13, 2022
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5...
Critical
Unreviewed
CVE-2018-14703
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API