GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,196 advisories
Filter by severity
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in...
High
Unreviewed
CVE-2016-1255
was published
May 17, 2022
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link...
High
Unreviewed
CVE-2022-30523
was published
May 17, 2022
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle...
Moderate
Unreviewed
CVE-2014-1876
was published
May 14, 2022
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or...
High
Unreviewed
CVE-2016-3108
was published
May 14, 2022
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to...
Moderate
Unreviewed
CVE-2014-4978
was published
May 14, 2022
Syncthing vulnerable to symlink traversal and arbitrary file overwrite
High
CVE-2017-1000420
was published
for
github.com/syncthing/syncthing
(Go)
May 14, 2022
VladTheEnterprising allows local users to write to arbitrary files via a symlink attack
Moderate
CVE-2014-4996
was published
for
VladTheEnterprising
(RubyGems)
May 14, 2022
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package...
High
Unreviewed
CVE-2013-4364
was published
May 14, 2022
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a...
Moderate
Unreviewed
CVE-2014-5509
was published
May 14, 2022
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have...
High
Unreviewed
CVE-2015-3315
was published
May 14, 2022
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows...
Moderate
Unreviewed
CVE-2017-18188
was published
May 14, 2022
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local,...
Moderate
Unreviewed
CVE-2018-1063
was published
May 14, 2022
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed...
Critical
Unreviewed
CVE-2018-5225
was published
May 14, 2022
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue...
Moderate
Unreviewed
CVE-2018-4112
was published
May 14, 2022
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary...
High
Unreviewed
CVE-2018-10380
was published
May 14, 2022
In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges...
High
Unreviewed
CVE-2018-10722
was published
May 14, 2022
The printing process can bypass local access protections to read files available through symlinks...
Moderate
Unreviewed
CVE-2018-5107
was published
May 14, 2022
The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6...
High
Unreviewed
CVE-2016-9774
was published
May 14, 2022
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs...
High
Unreviewed
CVE-2018-13054
was published
May 14, 2022
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write...
Moderate
Unreviewed
CVE-2014-4150
was published
May 14, 2022
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a...
Moderate
Unreviewed
CVE-2014-0243
was published
May 14, 2022
mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files...
Moderate
Unreviewed
CVE-2008-5373
was published
May 14, 2022
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the...
Low
Unreviewed
CVE-2011-1073
was published
May 14, 2022
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
High
Unreviewed
CVE-2015-7723
was published
May 14, 2022
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE:...
High
Unreviewed
CVE-2015-7724
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API