GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,082 advisories
Filter by severity
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to...
Low
Unreviewed
CVE-2010-3691
was published
May 13, 2022
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a...
Low
Unreviewed
CVE-2014-7206
was published
May 13, 2022
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2011-1144
was published
May 13, 2022
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink...
Low
Unreviewed
CVE-2011-1072
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to...
Low
Unreviewed
CVE-2011-0702
was published
May 13, 2022
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software,...
Moderate
Unreviewed
CVE-2016-10374
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to...
Low
Unreviewed
CVE-2011-1031
was published
May 13, 2022
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink...
Moderate
Unreviewed
CVE-2012-5303
was published
May 13, 2022
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to...
High
Unreviewed
CVE-2017-15357
was published
May 13, 2022
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows...
Moderate
Unreviewed
CVE-2014-8585
was published
May 13, 2022
rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in...
Moderate
Unreviewed
CVE-2014-9512
was published
May 13, 2022
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly...
Moderate
Unreviewed
CVE-2014-5045
was published
May 13, 2022
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to...
Low
Unreviewed
CVE-2011-4028
was published
May 13, 2022
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is...
High
Unreviewed
CVE-2019-5674
was published
May 13, 2022
NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which...
High
Unreviewed
CVE-2019-5665
was published
May 13, 2022
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC)...
High
Unreviewed
CVE-2019-0841
was published
May 13, 2022
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly...
High
Unreviewed
CVE-2019-0572
was published
May 13, 2022
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly...
High
Unreviewed
CVE-2019-0574
was published
May 13, 2022
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function...
Moderate
Unreviewed
CVE-2018-14335
was published
May 13, 2022
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory...
High
Unreviewed
CVE-2018-12015
was published
May 13, 2022
Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS...
High
Unreviewed
CVE-2018-11637
was published
May 13, 2022
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2...
Low
Unreviewed
CVE-2015-0794
was published
May 13, 2022
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the...
High
Unreviewed
CVE-2019-8455
was published
May 13, 2022
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14;...
High
Unreviewed
CVE-2016-6664
was published
May 13, 2022
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary...
Moderate
Unreviewed
CVE-2010-3879
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API