GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
119 advisories
Filter by severity
Moodle vulnerable to symlink attack
Moderate
CVE-2008-5153
was published
for
moodle/moodle
(Composer)
May 17, 2022
ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack
Moderate
CVE-2010-4338
was published
for
ocrodjvu
(pip)
May 17, 2022
Openstack DBaaS (Trove) Improper Link Resolution Before File Access
Moderate
CVE-2015-3156
was published
for
trove
(pip)
May 17, 2022
pyxdg Arbitrary File Overwrite via Race Condition
Low
CVE-2014-1624
was published
for
pyxdg
(pip)
May 17, 2022
SaltStack Salt Insecure Temporary File Creation
High
CVE-2014-3563
was published
for
salt
(pip)
May 17, 2022
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
High
CVE-2017-1000420
was published
for
github.com/syncthing/syncthing
(Go)
May 14, 2022
VladTheEnterprising allows local users to write to arbitrary files via a symlink attack
Moderate
CVE-2014-4996
was published
for
VladTheEnterprising
(RubyGems)
May 14, 2022
eyeD3 is vulnerable to arbitrary file modification via symlink attack
Moderate
CVE-2014-1934
was published
for
eyeD3
(pip)
May 14, 2022
Improper Link Resolution Before File Access in logilab-commons
High
CVE-2014-1838
was published
for
logilab-common
(pip)
May 14, 2022
Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability
Critical
CVE-2018-12026
was published
for
passenger
(RubyGems)
May 14, 2022
Numpy arbitrary file write via symlink attack
High
CVE-2014-1859
was published
for
numpy
(pip)
May 14, 2022
Improper Link Resolution Before File Access in Suds
Moderate
CVE-2013-2217
was published
for
suds
(pip)
May 14, 2022
Mercurial missing symlink check
High
CVE-2017-1000115
was published
for
mercurial
(pip)
May 14, 2022
Puppet arbitrary file overwrite
Moderate
CVE-2011-3869
was published
for
puppet
(RubyGems)
May 14, 2022
Puppet allows local users to modify the permissions of arbitrary files
Moderate
CVE-2011-3870
was published
for
puppet
(RubyGems)
May 14, 2022
keycloak-httpd-client-install symlink attack vulnerability
Moderate
CVE-2017-15111
was published
for
keycloak-httpd-client-install
(pip)
May 14, 2022
Ansible Sandbox Escape via Symlink Attack
High
CVE-2015-6240
was published
for
ansible
(pip)
May 13, 2022
SoSReport Predictable Tmp File Names
High
CVE-2015-7529
was published
for
sosreport
(pip)
May 13, 2022
RubyGems Link Following vulnerability
High
CVE-2018-1000073
was published
for
org.jruby:jruby-stdlib
(RubyGems)
May 13, 2022
Improper Link Resolution Before File Access in pip
Moderate
CVE-2013-1888
was published
for
pip
(pip)
May 13, 2022
instack-undercloud vulnerable to symlink attack on tmp files
Moderate
CVE-2017-7549
was published
for
instack-undercloud
(pip)
May 13, 2022
Puppet arbitrary files overwrite via a symlink attack
Low
CVE-2010-0156
was published
for
puppet
(RubyGems)
May 2, 2022
Joomla! Open Redirect vulnerability
High
CVE-2008-3227
was published
for
joomla/framework
(Composer)
May 1, 2022
Hadoop symlink vulnerability
High
CVE-2012-2945
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API