GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
425 advisories
Filter by severity
Incorrect Default Permissions in Liferay Portal
Moderate
CVE-2022-42128
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Incorrect Default Permissions in Liferay Portal
Moderate
CVE-2022-42130
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Incorrect default permissions in the Intel(R) Support Android application before version v22.02...
Moderate
Unreviewed
CVE-2022-36367
was published
Nov 11, 2022
There is a vulnerability in permission verification during the Bluetooth pairing process....
Moderate
Unreviewed
CVE-2022-44548
was published
Nov 10, 2022
Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux ...
Moderate
Unreviewed
CVE-2020-36605
was published
Nov 1, 2022
The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission...
Moderate
Unreviewed
CVE-2020-5355
was published
Oct 21, 2022
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv...
Moderate
Unreviewed
CVE-2013-4281
was published
Oct 19, 2022
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP)...
Moderate
Unreviewed
CVE-2022-41748
was published
Oct 11, 2022
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through...
Moderate
Unreviewed
CVE-2022-41414
was published
Oct 7, 2022
parse-server's session object properties can be updated by foreign user if object ID is known
Moderate
CVE-2022-39225
was published
for
parse-server
(npm)
Sep 21, 2022
A permission bypass vulnerability in Huawei cross device task management could allow an attacker...
Moderate
Unreviewed
CVE-2021-46834
was published
Sep 21, 2022
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with...
Moderate
Unreviewed
CVE-2022-2528
was published
Sep 10, 2022
ansible-runner has default temporary files written to world R/W locations
Moderate
CVE-2021-3701
was published
for
ansible-runner
(pip)
Aug 24, 2022
Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4...
Moderate
Unreviewed
CVE-2021-44470
was published
Aug 19, 2022
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may...
Moderate
Unreviewed
CVE-2022-27500
was published
Aug 19, 2022
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4,...
Moderate
Unreviewed
CVE-2021-39087
was published
Aug 17, 2022
In PackageManager, there is a possible installed package disclosure due to a missing permission...
Moderate
Unreviewed
CVE-2022-20322
was published
Aug 13, 2022
In ConnectivityService, there is a possible bypass of network permissions due to a missing...
Moderate
Unreviewed
CVE-2022-20341
was published
Aug 13, 2022
In ContentService, there is a possible way to check if an account exists on the device due to a...
Moderate
Unreviewed
CVE-2022-20296
was published
Aug 13, 2022
In ContentService, there is a possible way to check if an account exists on the device due to a...
Moderate
Unreviewed
CVE-2022-20298
was published
Aug 13, 2022
In ContentService, there is a possible way to check if the given account exists on the device due...
Moderate
Unreviewed
CVE-2022-20299
was published
Aug 13, 2022
In Content, there is a possible way to learn about an account present on the device due to a...
Moderate
Unreviewed
CVE-2022-20294
was published
Aug 13, 2022
In Content, there is a possible way to check if an account exists on the device due to a missing...
Moderate
Unreviewed
CVE-2022-20301
was published
Aug 13, 2022
In Content, there is a possible way to check if the given account exists on the device due to a...
Moderate
Unreviewed
CVE-2022-20300
was published
Aug 13, 2022
In ContentService, there is a possible way to determine if an account is on the device without...
Moderate
Unreviewed
CVE-2022-20303
was published
Aug 13, 2022
ProTip!
Advisories are also available from the
GraphQL API