GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,133
Erlang
29
GitHub Actions
19
Go
1,940
Maven
5,000+
npm
3,677
NuGet
645
pip
3,295
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
57 advisories
Filter by severity
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated...
Moderate
Unreviewed
CVE-2024-9333
was published
Oct 2, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-44188
was published
Sep 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-40859
was published
Sep 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-40831
was published
Sep 17, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-27858
was published
Sep 17, 2024
Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a...
Moderate
Unreviewed
CVE-2024-33892
was published
Aug 2, 2024
Improperly calculated effective permissions in M-Files Server versions 23.9 and 23.10 and 23.11...
Moderate
Unreviewed
CVE-2023-6239
was published
Nov 28, 2023
Anope before 2.0.15 does not prevent resetting the password of a suspended account.
Moderate
Unreviewed
CVE-2024-30187
was published
Mar 25, 2024
A non-admin user can change or remove important features within the Zabbix Agent application,...
Moderate
Unreviewed
CVE-2024-22121
was published
Aug 12, 2024
User with no permission to any of the Hosts can access and view host count & other statistics...
Moderate
Unreviewed
CVE-2024-22114
was published
Aug 12, 2024
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory....
Moderate
Unreviewed
CVE-2022-47637
was published
Sep 13, 2023
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time...
Moderate
Unreviewed
CVE-2023-21249
was published
Jul 13, 2023
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables...
Moderate
Unreviewed
CVE-2023-2818
was published
Jun 27, 2023
A valid, authenticated user with limited privileges may be able to use specifically crafted web...
Moderate
Unreviewed
CVE-2023-2993
was published
Jun 26, 2023
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64...
Moderate
Unreviewed
CVE-2019-20384
was published
May 24, 2022
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without...
Moderate
Unreviewed
CVE-2019-14956
was published
May 24, 2022
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x...
Moderate
Unreviewed
CVE-2019-6995
was published
May 24, 2022
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before...
Moderate
Unreviewed
CVE-2019-6791
was published
May 24, 2022
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through...
Moderate
Unreviewed
CVE-2024-21816
was published
Mar 4, 2024
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version,...
Moderate
Unreviewed
CVE-2024-0674
was published
Jan 30, 2024
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and...
Moderate
Unreviewed
CVE-2002-2323
was published
Apr 30, 2022
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories...
Moderate
Unreviewed
CVE-2001-1515
was published
Apr 30, 2022
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the...
Moderate
Unreviewed
CVE-2005-1920
was published
May 1, 2022
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file...
Moderate
Unreviewed
CVE-2020-16910
was published
May 24, 2022
Netskope was made aware of a security vulnerability in its NSClient product for version 100 &...
Moderate
Unreviewed
CVE-2023-4996
was published
Nov 6, 2023
ProTip!
Advisories are also available from the
GraphQL API