GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,082 advisories
Filter by severity
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to...
High
Unreviewed
CVE-2015-1130
was published
May 17, 2022
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk...
High
Unreviewed
CVE-2015-1338
was published
May 17, 2022
The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to...
Low
Unreviewed
CVE-2010-5105
was published
May 17, 2022
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain...
High
Unreviewed
CVE-2015-6566
was published
May 17, 2022
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a...
Low
Unreviewed
CVE-2015-0858
was published
May 17, 2022
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2014-3424
was published
May 17, 2022
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite...
Low
Unreviewed
CVE-2014-3422
was published
May 17, 2022
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2014-3423
was published
May 17, 2022
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2014-3421
was published
May 17, 2022
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a...
Low
Unreviewed
CVE-2012-1088
was published
May 17, 2022
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in...
Low
Unreviewed
CVE-2013-4262
was published
May 17, 2022
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges...
Low
Unreviewed
CVE-2013-7393
was published
May 17, 2022
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users...
Moderate
Unreviewed
CVE-2012-3440
was published
May 17, 2022
lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a...
Low
Unreviewed
CVE-2014-4703
was published
May 17, 2022
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates...
High
Unreviewed
CVE-2016-7490
was published
May 17, 2022
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x...
Moderate
Unreviewed
CVE-2015-3436
was published
May 17, 2022
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) -...
Low
Unreviewed
CVE-2015-4155
was published
May 17, 2022
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool ...
Low
Unreviewed
CVE-2015-5273
was published
May 17, 2022
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
Moderate
Unreviewed
CVE-2015-5287
was published
May 17, 2022
rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1,...
Moderate
Unreviewed
CVE-2013-4214
was published
May 17, 2022
Location Framework in Apple iOS before 8.4.1 allows local users to bypass intended restrictions...
Moderate
Unreviewed
CVE-2015-3759
was published
May 17, 2022
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem...
Moderate
Unreviewed
CVE-2015-5752
was published
May 17, 2022
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib...
Moderate
Unreviewed
CVE-2014-3486
was published
May 17, 2022
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files...
Low
Unreviewed
CVE-2014-3537
was published
May 17, 2022
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to ...
Moderate
Unreviewed
CVE-2014-4038
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API