GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,201 advisories
Filter by severity
Ghost vulnerable to arbitrary file read via symlinks in content import
Moderate
CVE-2023-40028
was published
for
ghost
(npm)
Aug 15, 2023
keycloak-httpd-client-install symlink attack vulnerability
Moderate
CVE-2017-15111
was published
for
keycloak-httpd-client-install
(pip)
May 14, 2022
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
High
CVE-2017-1000420
was published
for
github.com/syncthing/syncthing
(Go)
May 14, 2022
Podman Symlink Vulnerability
Moderate
CVE-2019-18466
was published
for
github.com/containers/podman/v4
(Go)
May 24, 2022
A symlink following vulnerability was found in Samba, where a user can create a symbolic link...
Moderate
Unreviewed
CVE-2022-3592
was published
Jan 12, 2023
Kubernetes kubectl cp Vulnerable to Symlink Attack
Moderate
CVE-2019-11251
was published
for
k8s.io/kubernetes
(Go)
May 18, 2021
Symlink Attack in kubectl cp
Moderate
CVE-2019-1002101
was published
for
k8s.io/kubernetes
(Go)
Feb 15, 2022
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink...
Moderate
Unreviewed
CVE-2021-44141
was published
Feb 22, 2022
Jekyll allows attackers to access arbitrary files by specifying a symlink
High
CVE-2018-17567
was published
for
jekyll
(RubyGems)
Sep 28, 2018
Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability...
Moderate
Unreviewed
CVE-2022-43293
was published
Apr 11, 2023
Hadoop symlink vulnerability
High
CVE-2012-2945
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 23, 2022
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
Critical
CVE-2018-1000544
was published
for
rubyzip
(RubyGems)
Sep 6, 2018
b3log Wide unauthenticated file access
High
CVE-2019-13915
was published
for
github.com/b3log/wide
(Go)
May 24, 2022
Podman Path Traversal Vulnerability leads to arbitrary file read/write
High
CVE-2019-10152
was published
for
github.com/containers/podman
(Go)
May 24, 2022
Cargo extracting malicious crates can corrupt arbitrary files
Low
CVE-2022-36113
was published
for
cargo
(Rust)
Sep 16, 2022
A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical....
High
Unreviewed
CVE-2022-4563
was published
Dec 21, 2022
eyeD3 is vulnerable to arbitrary file modification via symlink attack
Moderate
CVE-2014-1934
was published
for
eyeD3
(pip)
May 14, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31219
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31218
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31216
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31217
was published
Jun 16, 2022
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco...
High
Unreviewed
CVE-2022-20720
was published
Apr 16, 2022
binwalk vulnerable to UNIX Symbolic Link (Symlink) Following
Moderate
CVE-2021-4287
was published
for
binwalk
(pip)
Dec 27, 2022
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0...
Moderate
Unreviewed
CVE-2022-45440
was published
Jan 17, 2023
ProTip!
Advisories are also available from the
GraphQL API