GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,056
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
507 advisories
Filter by severity
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client...
High
Unreviewed
CVE-2024-23459
was published
May 2, 2024
Azure Monitor Agent Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-29989
was published
Apr 9, 2024
Microsoft Brokering File System Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-28907
was published
Apr 9, 2024
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26216
was published
Apr 9, 2024
Microsoft Install Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26158
was published
Apr 9, 2024
Windows Authentication Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-21447
was published
Apr 9, 2024
The CloudStack management server and secondary storage VM could be tricked into making requests...
High
Unreviewed
CVE-2024-29007
was published
Apr 4, 2024
An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp...
High
Unreviewed
CVE-2023-41969
was published
Mar 26, 2024
Malicious directory junction can cause WiX RemoveFoldersEx to possibly delete elevated files
High
CVE-2024-29188
was published
for
WixToolset.Util.wixext
(NuGet)
Mar 25, 2024
Xbox Gaming Services Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-28916
was published
Mar 21, 2024
Microsoft Office Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26199
was published
Mar 12, 2024
Windows Update Stack Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-21432
was published
Mar 12, 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma...
High
Unreviewed
CVE-2024-23285
was published
Mar 8, 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1,...
High
Unreviewed
CVE-2023-42942
was published
Feb 21, 2024
Azure Connected Machine Agent Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-21329
was published
Feb 13, 2024
HashiCorp Nomad vulnerable to symlink attacks
High
CVE-2024-1329
was published
for
github.com/hashicorp/nomad
(Go)
Feb 8, 2024
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote...
High
Unreviewed
CVE-2023-7216
was published
Feb 5, 2024
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One -...
High
Unreviewed
CVE-2023-52338
was published
Jan 23, 2024
A security agent link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52092
was published
Jan 23, 2024
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52091
was published
Jan 23, 2024
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local...
High
Unreviewed
CVE-2023-52094
was published
Jan 23, 2024
A security agent link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52090
was published
Jan 23, 2024
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47192
was published
Jan 23, 2024
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce...
High
Unreviewed
CVE-2023-6336
was published
Jan 16, 2024
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can...
High
Unreviewed
CVE-2023-42137
was published
Jan 15, 2024
ProTip!
Advisories are also available from the
GraphQL API