GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
58 advisories
Filter by severity
Incorrect Permission Assignment for Critical Resource in Apache hive
Low
CVE-2018-1315
was published
for
org.apache.hive:hive
(Maven)
Nov 21, 2018
A user without PR can reset user authentication failures information
Low
CVE-2021-32729
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-script
(Maven)
Jul 2, 2021
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to...
Low
Unreviewed
CVE-2022-24236
was published
Mar 22, 2022
Description: A permissions issue was addressed with improved validation. This issue is fixed in...
Low
Unreviewed
CVE-2022-22599
was published
Mar 19, 2022
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt...
Low
Unreviewed
CVE-2019-18899
was published
May 24, 2022
Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol...
Low
Unreviewed
CVE-2018-17766
was published
May 24, 2022
IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission...
Low
Unreviewed
CVE-2022-34314
was published
Nov 15, 2022
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log...
Low
Unreviewed
CVE-2019-3866
was published
May 24, 2022
ZTE E8820V3 router product is impacted by a permission and access control vulnerability....
Low
Unreviewed
CVE-2020-6863
was published
May 24, 2022
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service...
Low
Unreviewed
CVE-2020-1084
was published
May 24, 2022
An exposure of sensitive information flaw was found in Ansible Tower before version 3.7.1....
Low
Unreviewed
CVE-2020-10782
was published
May 24, 2022
Hashicorp Vault Privilege Escalation Vulnerability
Low
CVE-2021-41802
was published
for
github.com/hashicorp/vault
(Go)
Oct 12, 2021
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only....
Low
Unreviewed
CVE-2019-20883
was published
May 24, 2022
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service...
Low
Unreviewed
CVE-2020-1123
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5...
Low
Unreviewed
CVE-2020-4414
was published
May 24, 2022
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does...
Low
Unreviewed
CVE-2020-13696
was published
May 24, 2022
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2,...
Low
Unreviewed
CVE-2009-2948
was published
May 2, 2022
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb...
Low
Unreviewed
CVE-2008-3789
was published
May 2, 2022
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE)...
Low
Unreviewed
CVE-2021-34758
was published
May 24, 2022
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user...
Low
Unreviewed
CVE-2022-20330
was published
Aug 13, 2022
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable...
Low
Unreviewed
CVE-2008-4870
was published
May 13, 2022
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red...
Low
Unreviewed
CVE-2011-4339
was published
May 13, 2022
An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of...
Low
Unreviewed
CVE-2019-7729
was published
May 13, 2022
Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10,...
Low
Unreviewed
CVE-2017-15352
was published
May 13, 2022
IBM Tivoli Workload Scheduler 8.6.0, 9.1.0, and 9.2.0 could disclose sensitive information to a...
Low
Unreviewed
CVE-2017-1716
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API