GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      452 advisories
        Filter by severity
        
      
      
    
                    
                      Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9869
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability....
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9870
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9871
                      
                      was published
                      Oct 29, 2025 
                    
                  
                    
                      A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12341
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in XBox Gaming Services allows an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59281
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Windows Health and Optimized...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59241
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9968
                      
                      was published
                      Oct 13, 2025 
                    
                  
                    
                      Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (Windows client...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34194
                      
                      was published
                      Sep 19, 2025 
                    
                  
                    
                      Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-34191
                      
                      was published
                      Sep 19, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU)...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55317
                      
                      was published
                      Sep 9, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Xbox allows an authorized...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55245
                      
                      was published
                      Sep 9, 2025 
                    
                  
                    
                      AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8612
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5296
                      
                      was published
                      Aug 18, 2025 
                    
                  
                    
                      Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-36611
                      
                      was published
                      Jul 30, 2025 
                    
                  
                    
                      An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-7012
                      
                      was published
                      Jul 13, 2025 
                    
                  
                    
                      Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52837
                      
                      was published
                      Jul 10, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Microsoft PC Manager allows an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49738
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Visual Studio allows an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49739
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Windows AppX Deployment Service...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-48820
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Windows Performance Recorder...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49680
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      Improper link resolution before file access ('link following') in Windows Update Service allows...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-48799
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      A low privileged remote attacker with file access can replace a critical file used by the arp...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41667
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      A low privileged remote attacker with file access can replace a critical file or folder used by...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41668
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      A low privileged remote attacker with file access can replace a critical file used by the...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41666
                      
                      was published
                      Jul 8, 2025 
                    
                  
                    
                      A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3771
                      
                      was published
                      Jun 26, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API