GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
90 advisories
Filter by severity
A security vulnerability has been detected in sambitraj Student-Management-System up to...
Low
Unreviewed
CVE-2026-82697
was published
Aug 31, 2026
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its...
Low
Unreviewed
CVE-2026-59292
was published
Aug 27, 2026
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode...
Low
Unreviewed
CVE-2026-79783
was published
Aug 25, 2026
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks...
Low
Unreviewed
CVE-2026-76371
was published
Aug 20, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions...
Low
Unreviewed
CVE-2025-59866
was published
Jul 17, 2026
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
Low
CVE-2026-35361
was published
for
uu_mknod
(Rust)
Jul 6, 2026
mkdir: -m exposes directory with umask perms before chmod (race window)
Low
CVE-2026-35353
was published
for
uu_mkdir
(Rust)
Jul 6, 2026
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Low
CVE-2026-54327
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
The application does not impose strict enough restrictions on directory access permissions,...
Low
Unreviewed
CVE-2026-32684
was published
May 12, 2026
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique...
Low
Unreviewed
CVE-2026-6499
was published
May 4, 2026
GNU nano creates the user’s ~/.local directory with overly permissive permissions when the...
Low
Unreviewed
CVE-2026-40556
was published
Apr 28, 2026
uutils coreutils has an Incorrect Permission Assignment for Critical Resource
Low
CVE-2026-35367
was published
for
coreutils
(Rust)
Apr 22, 2026
A flaw was found in nano. In environments with permissive umask settings, a local attacker can...
Low
Unreviewed
CVE-2026-6842
was published
Apr 22, 2026
---
title: Cross-Tenant Legacy Correlation Disclosure and Deletion
draft: false
hero:
image: ...
Low
Unreviewed
CVE-2026-21727
was published
Apr 15, 2026
OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix)
Low
CVE-2026-41911
was published
for
openclaw
(npm)
Apr 9, 2026
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission...
Low
Unreviewed
CVE-2026-28264
was published
Apr 8, 2026
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()`...
Low
Unreviewed
CVE-2026-21715
was published
Mar 30, 2026
When
a certificate and its private key are installed in the Windows machine
certificate store...
Low
Unreviewed
CVE-2026-4761
was published
Mar 25, 2026
Freedombox before 25.17.1 does not set proper permissions for the backups-data directory,...
Low
Unreviewed
CVE-2025-68462
was published
Dec 18, 2025
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4)....
Low
Unreviewed
CVE-2025-40818
was published
Dec 9, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions
Low
CVE-2025-59349
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged...
Low
Unreviewed
CVE-2025-0164
was published
Sep 14, 2025
The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build...
Low
Unreviewed
CVE-2025-52992
was published
Jun 27, 2025
Fess has Insecure Temporary File Permissions
Low
CVE-2025-48382
was published
for
org.codelibs.fess:fess
(Maven)
May 27, 2025
ProTip!
Advisories are also available from the
GraphQL API