GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,498 advisories
Filter by severity
In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during...
High
Unreviewed
CVE-2026-16247
was published
Jul 20, 2026
In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As...
High
Unreviewed
CVE-2026-16246
was published
Jul 20, 2026
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ......
Low
Unreviewed
CVE-2024-58356
was published
Jul 18, 2026
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
High
Unreviewed
CVE-2023-54366
was published
Jul 18, 2026
CVE-2026-40952 is a privilege misconfiguration
in the Secure Access installer for the Windows...
High
Unreviewed
CVE-2026-40952
was published
Jul 15, 2026
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
Critical
CVE-2026-52766
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27464
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27463
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27462
was published
Jul 9, 2026
Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can...
High
Unreviewed
CVE-2026-57895
was published
Jul 8, 2026
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\....
High
Unreviewed
CVE-2026-57919
was published
Jun 29, 2026
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
Moderate
CVE-2026-48790
was published
for
github.com/tursodatabase/turso-cli
(Go)
Jun 26, 2026
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user...
Moderate
Unreviewed
CVE-2026-57924
was published
Jun 26, 2026
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was...
Low
Unreviewed
CVE-2026-48935
was published
Jun 26, 2026
nextflow auth login command has incorrect default permissions
Moderate
CVE-2026-48722
was published
for
io.nextflow:nextflow
(Maven)
Jun 25, 2026
Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev)...
Moderate
Unreviewed
CVE-2026-56301
was published
Jun 23, 2026
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability...
High
Unreviewed
CVE-2026-12602
was published
Jun 22, 2026
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
Moderate
CVE-2026-53856
was published
for
openclaw
(npm)
Jun 18, 2026
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
Moderate
CVE-2026-53870
was published
for
hermes-agent
(pip)
Jun 17, 2026
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a...
Moderate
Unreviewed
CVE-2025-15642
was published
Jun 17, 2026
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
GHSA-534h-c3cw-v3h9
was published
for
nuxt
(npm)
Jun 16, 2026
Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and...
Moderate
Unreviewed
CVE-2026-50255
was published
Jun 16, 2026
Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose...
Moderate
Unreviewed
CVE-2026-11931
was published
Jun 15, 2026
Apache ActiveMQ has an Incorrect Default Permissions vulnerability
High
CVE-2026-49157
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module...
Low
Unreviewed
CVE-2026-48190
was published
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API