GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
99 advisories
Filter by severity
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a...
Moderate
Unreviewed
CVE-2019-13727
was published
May 24, 2022
Missing permission check in Jenkins Support Core Plugin
Moderate
CVE-2019-16539
was published
for
org.jenkins-ci.plugins:support-core
(Maven)
May 24, 2022
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without...
Moderate
Unreviewed
CVE-2019-14956
was published
May 24, 2022
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before...
Moderate
Unreviewed
CVE-2019-6791
was published
May 24, 2022
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x...
Moderate
Unreviewed
CVE-2019-6995
was published
May 24, 2022
Jython Improper Access Restrictions vulnerability
Moderate
CVE-2013-2027
was published
for
org.python:jython-standalone
(Maven)
May 14, 2022
Ansible Arbitrary File Overwrite Vulnerability
Moderate
CVE-2013-4260
was published
for
ansible
(pip)
May 14, 2022
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for...
Moderate
Unreviewed
CVE-2018-3762
was published
May 13, 2022
Smarty Does Not Consider Umask Values When Setting Permissions
Moderate
CVE-2009-5054
was published
for
smarty/smarty
(Composer)
May 2, 2022
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the...
Moderate
Unreviewed
CVE-2005-1920
was published
May 1, 2022
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and...
Moderate
Unreviewed
CVE-2002-2323
was published
Apr 30, 2022
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories...
Moderate
Unreviewed
CVE-2001-1515
was published
Apr 30, 2022
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for...
Moderate
Unreviewed
CVE-2017-5033
was published
Apr 30, 2022
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the...
Moderate
Unreviewed
CVE-2021-43708
was published
Apr 22, 2022
Missing permission check in Jenkins Continuous Integration with Toad Edge Plugin
Moderate
CVE-2022-28147
was published
for
org.jenkins-ci.plugins:ci-with-toad-edge
(Maven)
Mar 30, 2022
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS...
Moderate
Unreviewed
CVE-2022-22650
was published
Mar 19, 2022
Missing permission checks in Jenkins Release Helper Plugin
Moderate
CVE-2022-27215
was published
for
org.jenkins-ci.plugins:release-helper
(Maven)
Mar 16, 2022
In enqueueNotification of NetworkPolicyManagerService.java, there is a possible way to retrieve a...
Moderate
Unreviewed
CVE-2021-0653
was published
Dec 16, 2021
In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java,...
Moderate
Unreviewed
CVE-2021-0704
was published
Dec 16, 2021
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This...
Moderate
Unreviewed
CVE-2021-1010
was published
Dec 16, 2021
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine...
Moderate
Unreviewed
CVE-2021-1025
was published
Dec 16, 2021
There is an Improper permission control vulnerability in Huawei Smartphone.Successful...
Moderate
Unreviewed
CVE-2021-37056
was published
Dec 8, 2021
Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki
Moderate
CVE-2021-3978
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 19, 2021
Insecure Permissions in Gogs
Moderate
CVE-2020-14958
was published
for
gogs.io/gogs
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API