GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,529 advisories
Filter by severity
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender...
High
Unreviewed
CVE-2026-100718
was published
Sep 26, 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows...
Moderate
Unreviewed
CVE-2026-6718
was published
Sep 23, 2026
Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default...
Moderate
Unreviewed
CVE-2026-82163
was published
Sep 21, 2026
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect...
Moderate
Unreviewed
CVE-2026-82165
was published
Sep 21, 2026
Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows...
Moderate
Unreviewed
CVE-2026-92252
was published
Sep 20, 2026
Local privilege escalation due to insecure file permissions. The following products are affected:...
High
Unreviewed
CVE-2026-87886
was published
Sep 18, 2026
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions...
High
Unreviewed
CVE-2026-86359
was published
Sep 16, 2026
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control...
High
Unreviewed
CVE-2026-86836
was published
Sep 14, 2026
A potential improper permissions vulnerability was reported in the Lenovo Filez Client...
High
Unreviewed
CVE-2026-11813
was published
Sep 10, 2026
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which...
High
Unreviewed
CVE-2026-77393
was published
Sep 5, 2026
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a...
High
Unreviewed
CVE-2026-81302
was published
Sep 4, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe...
High
Unreviewed
CVE-2026-9633
was published
Sep 1, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe...
High
Unreviewed
CVE-2026-9634
was published
Sep 1, 2026
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the...
High
Unreviewed
CVE-2026-81682
was published
Aug 27, 2026
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
High
Unreviewed
CVE-2026-69665
was published
Aug 25, 2026
RansomLook created its Flask session-signing key without explicitly restricting the file...
High
Unreviewed
CVE-2026-78553
was published
Aug 24, 2026
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized...
High
Unreviewed
CVE-2025-68825
was published
Aug 24, 2026
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability....
Moderate
Unreviewed
CVE-2026-18273
was published
Aug 20, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions...
High
Unreviewed
CVE-2026-58564
was published
Aug 19, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
During an internal security assessment, a potential improper permissions vulnerability was...
High
Unreviewed
CVE-2026-63425
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where the shared storage used by product components is...
Moderate
Unreviewed
CVE-2025-52640
was published
Aug 13, 2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary...
Moderate
Unreviewed
CVE-2026-65940
was published
Aug 12, 2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-59119
was published
Aug 11, 2026
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a...
Low
Unreviewed
CVE-2025-48505
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API