GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,070 advisories
Filter by severity
nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via...
High
Unreviewed
CVE-2003-1528
was published
Apr 29, 2022
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a...
Moderate
Unreviewed
CVE-2003-1492
was published
Apr 29, 2022
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers,...
Low
Unreviewed
CVE-2003-1233
was published
Apr 29, 2022
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode...
Low
Unreviewed
CVE-2003-0844
was published
Apr 29, 2022
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root,...
Moderate
Unreviewed
CVE-2003-0578
was published
Apr 29, 2022
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link...
Moderate
Unreviewed
CVE-2022-24372
was published
Apr 28, 2022
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink...
Moderate
Unreviewed
CVE-2012-1093
was published
Apr 23, 2022
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Moderate
Unreviewed
CVE-2011-5271
was published
Apr 23, 2022
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
Moderate
Unreviewed
CVE-2011-4116
was published
Apr 22, 2022
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local...
High
Unreviewed
CVE-2011-3632
was published
Apr 22, 2022
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system...
High
Unreviewed
CVE-2011-3351
was published
Apr 22, 2022
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2923
was published
Apr 22, 2022
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2924
was published
Apr 22, 2022
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
Moderate
Unreviewed
CVE-2010-4817
was published
Apr 21, 2022
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink...
High
Unreviewed
CVE-2010-2064
was published
Apr 21, 2022
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via...
Moderate
Unreviewed
CVE-2010-0398
was published
Apr 21, 2022
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2009-0035
was published
Apr 21, 2022
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco...
High
Unreviewed
CVE-2022-20720
was published
Apr 16, 2022
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low...
High
Unreviewed
CVE-2022-1256
was published
Apr 15, 2022
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution....
Moderate
Unreviewed
CVE-2022-20068
was published
Apr 12, 2022
VMware Horizon Client for Linux (prior to 22.x) contains a local privilege escalation as a user...
High
Unreviewed
CVE-2022-22962
was published
Apr 12, 2022
A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to...
High
Unreviewed
CVE-2022-27883
was published
Apr 10, 2022
The combination of primitives offered by SMB and AFP in their default configuration allows the...
Critical
Unreviewed
CVE-2022-22995
was published
Mar 27, 2022
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any...
High
Unreviewed
CVE-2022-26659
was published
Mar 26, 2022
An issue existed within the path validation logic for symlinks. This issue was addressed with...
High
Unreviewed
CVE-2022-22585
was published
Mar 19, 2022
ProTip!
Advisories are also available from the
GraphQL API