GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,196 advisories
Filter by severity
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper:...
Moderate
Unreviewed
CVE-2019-13229
was published
May 24, 2022
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to...
Moderate
Unreviewed
CVE-2019-13228
was published
May 24, 2022
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone...
Moderate
Unreviewed
CVE-2019-13227
was published
May 24, 2022
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename>...
High
Unreviewed
CVE-2019-13226
was published
May 24, 2022
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates...
High
Unreviewed
CVE-2019-1069
was published
May 24, 2022
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC)...
High
Unreviewed
CVE-2019-1064
was published
May 24, 2022
An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder...
High
Unreviewed
CVE-2019-1053
was published
May 24, 2022
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc)...
High
Unreviewed
CVE-2019-0986
was published
May 24, 2022
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in...
High
Unreviewed
CVE-2019-12749
was published
May 24, 2022
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because...
High
Unreviewed
CVE-2019-12779
was published
May 24, 2022
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico...
High
Unreviewed
CVE-2019-12209
was published
May 24, 2022
In some configurations an attacker can inject a new executable path into the extensions.load file...
High
Unreviewed
CVE-2019-3567
was published
May 24, 2022
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100...
High
Unreviewed
CVE-2019-9949
was published
May 24, 2022
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R)...
High
Unreviewed
CVE-2019-0086
was published
May 24, 2022
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security...
High
Unreviewed
CVE-2019-8454
was published
May 24, 2022
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX...
High
Unreviewed
CVE-2019-11538
was published
May 24, 2022
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing...
High
Unreviewed
CVE-2019-11503
was published
May 24, 2022
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid...
High
Unreviewed
CVE-2019-11502
was published
May 24, 2022
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point...
High
Unreviewed
CVE-2019-8452
was published
May 24, 2022
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server
Moderate
CVE-2022-24904
was published
for
github.com/argoproj/argo-cd/v2
(Go)
May 23, 2022
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can...
High
Unreviewed
CVE-2022-31258
was published
May 21, 2022
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2013-0200
was published
May 17, 2022
** DISPUTED ** postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a...
Moderate
Unreviewed
CVE-2008-4998
was published
May 17, 2022
pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp...
Moderate
Unreviewed
CVE-2008-4988
was published
May 17, 2022
** DISPUTED ** init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via...
Moderate
Unreviewed
CVE-2008-4996
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API