GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,056
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,195 advisories
Filter by severity
wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite...
Low
Unreviewed
CVE-2004-2473
was published
Apr 29, 2022
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack...
Moderate
Unreviewed
CVE-2004-1901
was published
Apr 29, 2022
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files...
Moderate
Unreviewed
CVE-2004-1603
was published
Apr 29, 2022
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations,...
Moderate
Unreviewed
CVE-2004-0689
was published
Apr 29, 2022
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red...
Low
Unreviewed
CVE-2004-0217
was published
Apr 29, 2022
nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via...
High
Unreviewed
CVE-2003-1528
was published
Apr 29, 2022
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a...
Moderate
Unreviewed
CVE-2003-1492
was published
Apr 29, 2022
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers,...
Low
Unreviewed
CVE-2003-1233
was published
Apr 29, 2022
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode...
Low
Unreviewed
CVE-2003-0844
was published
Apr 29, 2022
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root,...
Moderate
Unreviewed
CVE-2003-0578
was published
Apr 29, 2022
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link...
Moderate
Unreviewed
CVE-2022-24372
was published
Apr 28, 2022
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink...
Moderate
Unreviewed
CVE-2012-1093
was published
Apr 23, 2022
Hadoop symlink vulnerability
High
CVE-2012-2945
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 23, 2022
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Moderate
Unreviewed
CVE-2011-5271
was published
Apr 23, 2022
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
Moderate
Unreviewed
CVE-2011-4116
was published
Apr 22, 2022
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local...
High
Unreviewed
CVE-2011-3632
was published
Apr 22, 2022
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system...
High
Unreviewed
CVE-2011-3351
was published
Apr 22, 2022
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2923
was published
Apr 22, 2022
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2924
was published
Apr 22, 2022
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
Moderate
Unreviewed
CVE-2010-4817
was published
Apr 21, 2022
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via...
Moderate
Unreviewed
CVE-2010-0398
was published
Apr 21, 2022
rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink...
High
Unreviewed
CVE-2010-2064
was published
Apr 21, 2022
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2009-0035
was published
Apr 21, 2022
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco...
High
Unreviewed
CVE-2022-20720
was published
Apr 16, 2022
A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low...
High
Unreviewed
CVE-2022-1256
was published
Apr 15, 2022
ProTip!
Advisories are also available from the
GraphQL API