GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
72 advisories
Filter by severity
When
a certificate and its private key are installed in the Windows machine
certificate store...
Low
Unreviewed
CVE-2026-4761
was published
Mar 25, 2026
Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for...
Low
Unreviewed
CVE-2005-4868
was published
May 1, 2022
Information Disclosure in Guava
Low
CVE-2020-8908
was published
for
com.google.guava:guava
(Maven)
Mar 25, 2021
Freedombox before 25.17.1 does not set proper permissions for the backups-data directory,...
Low
Unreviewed
CVE-2025-68462
was published
Dec 18, 2025
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4)....
Low
Unreviewed
CVE-2025-40818
was published
Dec 9, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Low
Unreviewed
CVE-2025-21520
was published
Jan 21, 2025
Mattermost Server allows System Admin to modify LDAP account names and email addresses
Low
CVE-2016-11077
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Dragonfly's directories created via os.MkdirAll are not checked for permissions
Low
CVE-2025-59349
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged...
Low
Unreviewed
CVE-2025-0164
was published
Sep 14, 2025
The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build...
Low
Unreviewed
CVE-2025-52992
was published
Jun 27, 2025
Spring Cloud Contract vulnerable to local information disclosure
Low
CVE-2024-22236
was published
for
org.springframework.cloud:spring-cloud-contract-shade
(Maven)
Jan 31, 2024
Fess has Insecure Temporary File Permissions
Low
CVE-2025-48382
was published
for
org.codelibs.fess:fess
(Maven)
May 27, 2025
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3...
Low
Unreviewed
CVE-2019-13535
was published
May 24, 2022
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2,...
Low
Unreviewed
CVE-2009-2948
was published
May 2, 2022
In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the ...
Low
Unreviewed
CVE-2025-20233
was published
Mar 27, 2025
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the...
Low
Unreviewed
CVE-2024-52328
was published
Jan 23, 2025
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-27vq-hv74-7cqp
was published
for
surrealdb
(Rust)
Dec 16, 2024
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS...
Low
Unreviewed
CVE-2024-44575
was published
Sep 11, 2024
Improper export of Android application components issue exists in 'ABEMA' App for Android prior...
Low
Unreviewed
CVE-2024-28745
was published
Mar 18, 2024
Improper permission control in the mobile application (com.android.server.telecom) may lead to...
Low
Unreviewed
CVE-2024-6780
was published
Jul 16, 2024
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path...
Low
Unreviewed
CVE-2024-10228
was published
Oct 30, 2024
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier...
Low
Unreviewed
CVE-2024-46897
was published
Oct 18, 2024
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive...
Low
Unreviewed
CVE-2022-43845
was published
Sep 25, 2024
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754,...
Low
Unreviewed
CVE-2023-32114
was published
Jun 13, 2023
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform...
Low
Unreviewed
CVE-2023-49578
was published
Dec 12, 2023
ProTip!
Advisories are also available from the
GraphQL API