GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,357 advisories
Filter by severity
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions:...
High
Unreviewed
CVE-2017-13168
was published
May 13, 2022
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5)...
High
Unreviewed
CVE-2017-16895
was published
May 13, 2022
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to...
High
Unreviewed
CVE-2017-5260
was published
May 13, 2022
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write...
Moderate
Unreviewed
CVE-2017-15906
was published
May 13, 2022
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an...
Moderate
Unreviewed
CVE-2017-9792
was published
May 13, 2022
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software...
High
Unreviewed
CVE-2017-9958
was published
May 13, 2022
It was found that rhnsd PID files are created as world-writable that allows local attackers to...
Moderate
Unreviewed
CVE-2017-7560
was published
May 13, 2022
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary...
High
Unreviewed
CVE-2017-8665
was published
May 13, 2022
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions ...
High
Unreviewed
CVE-2017-11156
was published
May 13, 2022
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an...
Moderate
Unreviewed
CVE-2017-11437
was published
May 13, 2022
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could...
High
Unreviewed
CVE-2017-1000022
was published
May 13, 2022
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi...
High
Unreviewed
CVE-2017-8450
was published
May 13, 2022
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the...
Moderate
Unreviewed
CVE-2017-8449
was published
May 13, 2022
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer...
Critical
Unreviewed
CVE-2017-9602
was published
May 13, 2022
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has...
Moderate
Unreviewed
CVE-2017-9079
was published
May 13, 2022
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the...
High
Unreviewed
CVE-2017-7889
was published
May 13, 2022
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper...
High
Unreviewed
CVE-2017-3006
was published
May 13, 2022
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions...
Critical
Unreviewed
CVE-2017-6950
was published
May 13, 2022
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported...
Moderate
Unreviewed
CVE-2025-21583
was published
Apr 15, 2025
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search...
High
Unreviewed
CVE-2025-30708
was published
Apr 15, 2025
cnlh nps vulnerable to file overwrite by local user
Moderate
CVE-2019-15119
was published
for
ehang.io/nps
(Go)
May 24, 2022
SilverStripe Subsite weakens file permissions
Moderate
CVE-2022-42949
was published
for
silverstripe/subsites
(Composer)
Dec 19, 2022
Overview
The product specifies permissions for a security-critical resource in a way that...
Moderate
Unreviewed
CVE-2025-0758
was published
Apr 17, 2025
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected...
Moderate
Unreviewed
CVE-2025-21578
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). ...
Moderate
Unreviewed
CVE-2025-21579
was published
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API