GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,529 advisories
Filter by severity
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender...
High
Unreviewed
CVE-2026-100718
was published
Sep 26, 2026
A container privilege escalation flaw was found in certain Ansible Automation Platform images....
Moderate
Unreviewed
CVE-2025-57847
was published
Apr 8, 2026
IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows...
Moderate
Unreviewed
CVE-2026-6718
was published
Sep 23, 2026
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
CVE-2026-56301
was published
for
nuxt
(npm)
Jun 16, 2026
Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
GHSA-2x6f-57hp-86fx
was published
for
nuxt
(npm)
Jun 23, 2026
•
withdrawn
Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default...
Moderate
Unreviewed
CVE-2026-82163
was published
Sep 21, 2026
Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect...
Moderate
Unreviewed
CVE-2026-82165
was published
Sep 21, 2026
Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows...
Moderate
Unreviewed
CVE-2026-92252
was published
Sep 20, 2026
Local privilege escalation due to insecure file permissions. The following products are affected:...
High
Unreviewed
CVE-2026-87886
was published
Sep 18, 2026
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions...
High
Unreviewed
CVE-2026-86359
was published
Sep 16, 2026
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control...
High
Unreviewed
CVE-2026-86836
was published
Sep 14, 2026
A potential improper permissions vulnerability was reported in the Lenovo Filez Client...
High
Unreviewed
CVE-2026-11813
was published
Sep 10, 2026
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which...
High
Unreviewed
CVE-2026-77393
was published
Sep 5, 2026
SurrealDB: Full Table Permissions by Default
High
CVE-2023-54366
was published
for
surrealdb
(Rust)
Dec 15, 2023
Duplicate Advisory: Full Table Permissions by Default
High
GHSA-m8pp-qc66-6pgp
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-vmg6-53r4-jhpw
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a...
High
Unreviewed
CVE-2026-81302
was published
Sep 4, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe...
High
Unreviewed
CVE-2026-9633
was published
Sep 1, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe...
High
Unreviewed
CVE-2026-9634
was published
Sep 1, 2026
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows...
Critical
Unreviewed
CVE-2023-43902
was published
Nov 14, 2023
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the...
High
Unreviewed
CVE-2026-81682
was published
Aug 27, 2026
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
High
Unreviewed
CVE-2026-69665
was published
Aug 25, 2026
RansomLook created its Flask session-signing key without explicitly restricting the file...
High
Unreviewed
CVE-2026-78553
was published
Aug 24, 2026
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized...
High
Unreviewed
CVE-2025-68825
was published
Aug 24, 2026
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability....
Moderate
Unreviewed
CVE-2026-18273
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API