GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
927 advisories
Filter by severity
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary...
High
Unreviewed
CVE-2020-28407
was published
Nov 3, 2023
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video...
High
Unreviewed
CVE-2018-17559
was published
Oct 27, 2023
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma...
High
Unreviewed
CVE-2023-42844
was published
Oct 25, 2023
Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside...
High
Unreviewed
CVE-2023-28797
was published
Oct 23, 2023
1E Client installer can perform arbitrary file deletion on protected files.
A non-privileged...
High
Unreviewed
CVE-2023-45159
was published
Oct 5, 2023
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2023-41968
was published
Sep 27, 2023
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux...
High
Unreviewed
CVE-2023-32182
was published
Sep 19, 2023
Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-32163
was published
Sep 6, 2023
Local privilege escalation during installation due to improper soft link handling. The following...
High
Unreviewed
CVE-2022-46869
was published
Aug 31, 2023
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain...
High
Unreviewed
CVE-2023-34723
was published
Aug 26, 2023
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a...
High
Unreviewed
CVE-2019-13689
was published
Aug 25, 2023
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
High
Unreviewed
CVE-2022-48579
was published
Aug 7, 2023
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for...
Critical
Unreviewed
CVE-2023-39107
was published
Aug 4, 2023
The Firefox updater created a directory writable by non-privileged users. When uninstalling...
Moderate
Unreviewed
CVE-2023-4052
was published
Aug 1, 2023
A website could have obscured the full screen notification by using a URL with a scheme handled...
Moderate
Unreviewed
CVE-2023-4053
was published
Aug 1, 2023
Uploading files which contain symlinks may have allowed an attacker to trick a user into...
Moderate
Unreviewed
CVE-2023-37206
was published
Jul 5, 2023
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of...
High
Unreviewed
CVE-2023-27469
was published
Jun 30, 2023
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could...
Moderate
Unreviewed
CVE-2023-32556
was published
Jun 27, 2023
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an...
High
Unreviewed
CVE-2023-28065
was published
Jun 23, 2023
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain...
High
Unreviewed
CVE-2023-28071
was published
Jun 23, 2023
RenderDoc through 1.26 allows local privilege escalation via a symlink attack.
High
Unreviewed
CVE-2023-33865
was published
Jun 7, 2023
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90...
High
Unreviewed
CVE-2023-2939
was published
May 31, 2023
imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of...
Moderate
Unreviewed
CVE-2023-34204
was published
May 30, 2023
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and...
High
Unreviewed
CVE-2023-33245
was published
May 30, 2023
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution...
High
Unreviewed
CVE-2023-27529
was published
May 25, 2023
ProTip!
Advisories are also available from the
GraphQL API