GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
507 advisories
Filter by severity
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security...
High
Unreviewed
CVE-2021-23892
was published
May 24, 2022
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP)...
High
Unreviewed
CVE-2021-23872
was published
May 24, 2022
Windows WalletService Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-31187
was published
May 24, 2022
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root...
High
Unreviewed
CVE-2020-28007
was published
May 24, 2022
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability This CVE ID is...
High
Unreviewed
CVE-2021-28321
was published
May 24, 2022
VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for...
High
Unreviewed
CVE-2021-30463
was published
May 24, 2022
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it...
High
Unreviewed
CVE-2020-15075
was published
May 24, 2022
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6...
High
Unreviewed
CVE-2020-7346
was published
May 24, 2022
Microsoft Windows Folder Redirection Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26887
was published
May 24, 2022
Windows Update Stack Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26889
was published
May 24, 2022
Windows Update Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26866
was published
May 24, 2022
Windows User Profile Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26873
was published
May 24, 2022
Windows Installer Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26862
was published
May 24, 2022
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB...
High
Unreviewed
CVE-2021-3310
was published
May 24, 2022
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python...
High
Unreviewed
CVE-2020-12878
was published
May 24, 2022
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc...
High
Unreviewed
CVE-2021-26720
was published
May 24, 2022
Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a...
High
Unreviewed
CVE-2021-27229
was published
May 24, 2022
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker...
High
Unreviewed
CVE-2021-1278
was published
May 24, 2022
selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to...
High
Unreviewed
CVE-2021-23240
was published
May 24, 2022
The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges...
High
Unreviewed
CVE-2020-35766
was published
May 24, 2022
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system...
High
Unreviewed
CVE-2020-28641
was published
May 24, 2022
An issue existed within the path validation logic for symlinks. This issue was addressed with...
High
Unreviewed
CVE-2020-10003
was published
May 24, 2022
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could...
High
Unreviewed
CVE-2020-27697
was published
May 24, 2022
Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a...
High
Unreviewed
CVE-2020-23968
was published
May 24, 2022
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated...
High
Unreviewed
CVE-2020-5795
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API