GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
66 advisories
Filter by severity
SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ......
Low
Unreviewed
CVE-2024-58356
was published
Jul 18, 2026
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was...
Low
Unreviewed
CVE-2026-48935
was published
Jun 26, 2026
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module...
Low
Unreviewed
CVE-2026-48190
was published
Jun 1, 2026
An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above)...
Low
Unreviewed
CVE-2026-48191
was published
Jun 1, 2026
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP...
Low
Unreviewed
CVE-2026-27680
was published
May 14, 2026
A flaw in Node.js's permission model allows a file's access and modification timestamps to be...
Low
Unreviewed
CVE-2025-55132
was published
Jan 20, 2026
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without...
Low
Unreviewed
CVE-2025-12792
was published
Nov 18, 2025
Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in...
Low
Unreviewed
CVE-2025-36857
was published
Sep 25, 2025
The Nix, Lix, and Guix package managers default to using temporary build directories in a world...
Low
Unreviewed
CVE-2025-52991
was published
Jun 27, 2025
An incorrect default permissions vulnerability was reported in the MotoSignature application that...
Low
Unreviewed
CVE-2025-1699
was published
Jun 11, 2025
An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can...
Low
Unreviewed
CVE-2024-53921
was published
Dec 3, 2024
HCL Connections is vulnerable to a broken access control vulnerability that may allow an...
Low
Unreviewed
CVE-2024-42188
was published
Nov 14, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2024-40792
was published
Oct 28, 2024
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported...
Low
Unreviewed
CVE-2024-21123
was published
Jul 17, 2024
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk®...
Low
Unreviewed
CVE-2024-6326
was published
Jul 16, 2024
It was identified that in certain versions of Octopus Server, that a user created with no...
Low
Unreviewed
CVE-2024-4226
was published
Apr 30, 2024
MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine...
Low
Unreviewed
CVE-2023-46270
was published
Apr 29, 2024
Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version...
Low
Unreviewed
CVE-2024-32368
was published
Apr 22, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21004
was published
Apr 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21002
was published
Apr 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21012
was published
Apr 17, 2024
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
Low
Unreviewed
CVE-2024-30204
was published
Mar 25, 2024
Local privilege escalation due to insecure folder permissions. The following products are...
Low
Unreviewed
CVE-2023-44157
was published
Sep 27, 2023
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1...
Low
Unreviewed
CVE-2023-21512
was published
Jun 28, 2023
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location...
Low
Unreviewed
CVE-2022-20240
was published
Dec 13, 2022
ProTip!
Advisories are also available from the
GraphQL API