GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,140
Maven
5,000+
npm
3,800
NuGet
687
pip
3,478
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
431 advisories
Filter by severity
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with...
High
Unreviewed
CVE-2022-34893
was published
Sep 20, 2022
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows...
High
Unreviewed
CVE-2008-1078
was published
May 1, 2022
aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the...
High
Unreviewed
CVE-2008-1901
was published
May 1, 2022
BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can...
High
Unreviewed
CVE-2008-0870
was published
May 1, 2022
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact...
High
Unreviewed
CVE-2008-3329
was published
May 1, 2022
w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print...
High
Unreviewed
CVE-2008-0930
was published
May 1, 2022
Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900...
High
Unreviewed
CVE-2008-3521
was published
May 2, 2022
A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to...
High
Unreviewed
CVE-2008-4406
was published
May 2, 2022
ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary...
High
Unreviewed
CVE-2008-4475
was published
May 2, 2022
configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack...
High
Unreviewed
CVE-2008-3883
was published
May 2, 2022
genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink...
High
Unreviewed
CVE-2008-3927
was published
May 2, 2022
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink...
High
Unreviewed
CVE-2008-3929
was published
May 2, 2022
Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow...
High
Unreviewed
CVE-2008-4108
was published
May 2, 2022
freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a...
High
Unreviewed
CVE-2008-4474
was published
May 2, 2022
The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a...
High
Unreviewed
CVE-2008-4440
was published
May 2, 2022
alert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary files via a symlink...
High
Unreviewed
CVE-2008-4477
was published
May 2, 2022
qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite...
High
Unreviewed
CVE-2008-4553
was published
May 2, 2022
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended...
High
Unreviewed
CVE-2009-1143
was published
Nov 23, 2022
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs...
High
Unreviewed
CVE-2004-0967
was published
May 3, 2022
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1...
High
Unreviewed
CVE-2013-0159
was published
May 5, 2022
An improper link resolution before file access ('Link Following') vulnerability has been reported...
High
Unreviewed
CVE-2021-44052
was published
May 6, 2022
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for...
High
Unreviewed
CVE-2022-23742
was published
May 13, 2022
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink...
High
Unreviewed
CVE-2018-10928
was published
May 13, 2022
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path...
High
Unreviewed
CVE-2018-6954
was published
May 13, 2022
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6...
High
Unreviewed
CVE-2016-1247
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API