GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,520 advisories
Filter by severity
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which...
High
Unreviewed
CVE-2026-77393
was published
Sep 5, 2026
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a...
High
Unreviewed
CVE-2026-81302
was published
Sep 4, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe...
High
Unreviewed
CVE-2026-9634
was published
Sep 1, 2026
A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe...
High
Unreviewed
CVE-2026-9633
was published
Sep 1, 2026
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the...
High
Unreviewed
CVE-2026-81682
was published
Aug 27, 2026
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
High
Unreviewed
CVE-2026-69665
was published
Aug 25, 2026
RansomLook created its Flask session-signing key without explicitly restricting the file...
High
Unreviewed
CVE-2026-78553
was published
Aug 24, 2026
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized...
High
Unreviewed
CVE-2025-68825
was published
Aug 24, 2026
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability....
Moderate
Unreviewed
CVE-2026-18273
was published
Aug 20, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions...
High
Unreviewed
CVE-2026-58564
was published
Aug 19, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
During an internal security assessment, a potential improper permissions vulnerability was...
High
Unreviewed
CVE-2026-63425
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where the shared storage used by product components is...
Moderate
Unreviewed
CVE-2025-52640
was published
Aug 13, 2026
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary...
Moderate
Unreviewed
CVE-2026-65940
was published
Aug 12, 2026
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-59119
was published
Aug 11, 2026
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a...
Low
Unreviewed
CVE-2025-48505
was published
Aug 11, 2026
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a...
Low
Unreviewed
CVE-2025-61970
was published
Aug 11, 2026
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to...
High
Unreviewed
CVE-2026-21074
was published
Aug 10, 2026
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows...
High
Unreviewed
CVE-2026-4793
was published
Aug 3, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2026-39874
was published
Jul 27, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2026-39875
was published
Jul 27, 2026
In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during...
High
Unreviewed
CVE-2026-16247
was published
Jul 20, 2026
In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As...
High
Unreviewed
CVE-2026-16246
was published
Jul 20, 2026
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-vmg6-53r4-jhpw
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: Full Table Permissions by Default
High
GHSA-m8pp-qc66-6pgp
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API