GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,205 advisories
Filter by severity
There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to...
High
Unreviewed
CVE-2021-22311
was published
May 24, 2022
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This...
Moderate
Unreviewed
CVE-2021-21438
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5...
Moderate
Unreviewed
CVE-2020-4976
was published
May 24, 2022
In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass...
Moderate
Unreviewed
CVE-2021-0381
was published
May 24, 2022
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to...
Moderate
Unreviewed
CVE-2021-0382
was published
May 24, 2022
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This...
High
Unreviewed
CVE-2021-0389
was published
May 24, 2022
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify...
High
Unreviewed
CVE-2021-0380
was published
May 24, 2022
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042...
Moderate
Unreviewed
CVE-2020-8357
was published
May 24, 2022
Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers...
Moderate
Unreviewed
CVE-2021-25344
was published
May 24, 2022
In the Zstandard command-line utility prior to v1.4.1, output files were created with default...
Critical
Unreviewed
CVE-2021-24031
was published
May 24, 2022
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the...
Critical
Unreviewed
CVE-2021-24032
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13554
was published
May 24, 2022
"Tasks" application version before 9.7.3 is affected by insecure permissions. The...
Moderate
Unreviewed
CVE-2020-22475
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13549
was published
May 24, 2022
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6...
High
Unreviewed
CVE-2020-36233
was published
May 24, 2022
Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and...
Moderate
Unreviewed
CVE-2021-20653
was published
May 24, 2022
Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021...
Moderate
Unreviewed
CVE-2020-8701
was published
May 24, 2022
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a...
Moderate
Unreviewed
CVE-2020-8765
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13555
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13551
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13552
was published
May 24, 2022
An exploitable local privilege elevation vulnerability exists in the file system permissions of...
High
Unreviewed
CVE-2020-13553
was published
May 24, 2022
Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of...
Moderate
Unreviewed
CVE-2020-0524
was published
May 24, 2022
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1...
High
Unreviewed
CVE-2021-3394
was published
May 24, 2022
A vulnerability has been identified in SIMARIS configuration (All versions). During installation...
High
Unreviewed
CVE-2020-28392
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API