GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,059 advisories
Filter by severity
The (1) rccs and (2) STUFF scripts in lmbench 3.0-a7 allow local users to overwrite arbitrary...
Moderate
Unreviewed
CVE-2008-4968
was published
May 17, 2022
asciiview in aview 1.3.0 allows local users to overwrite arbitrary files via a symlink attack on...
Moderate
Unreviewed
CVE-2008-4935
was published
May 17, 2022
gdrae in gdrae 0.1 allows local users to overwrite arbitrary files via a symlink attack on the ...
Moderate
Unreviewed
CVE-2008-4958
was published
May 17, 2022
mailgo in mgt 2.31 allows local users to overwrite arbitrary files via a symlink attack on a /tmp...
Moderate
Unreviewed
CVE-2008-4972
was published
May 17, 2022
xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp...
Moderate
Unreviewed
CVE-2008-4987
was published
May 17, 2022
runiozone in lustre 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on...
Moderate
Unreviewed
CVE-2008-4970
was published
May 17, 2022
Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server
Moderate
CVE-2022-31036
was published
for
github.com/argoproj/argo-cd
(Go)
Jun 21, 2022
Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from...
High
Unreviewed
CVE-2022-2145
was published
Jun 29, 2022
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files...
Moderate
Unreviewed
CVE-2015-8326
was published
May 17, 2022
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure...
High
Unreviewed
CVE-2021-42056
was published
Jun 25, 2022
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks...
Moderate
Unreviewed
CVE-2015-0556
was published
May 17, 2022
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the...
Moderate
Unreviewed
CVE-2012-3345
was published
May 17, 2022
Insecure Temporary File in SWHKD
Critical
CVE-2022-27815
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Mar 31, 2022
In sound driver, there is a possible information disclosure due to symlink following. This could...
Moderate
Unreviewed
CVE-2022-21770
was published
Jul 7, 2022
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root...
Low
Unreviewed
CVE-2015-6927
was published
May 17, 2022
acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to...
Low
Unreviewed
CVE-2014-3981
was published
May 17, 2022
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a...
Low
Unreviewed
CVE-2014-5029
was published
May 17, 2022
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to ...
Moderate
Unreviewed
CVE-2014-4038
was published
May 17, 2022
A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows...
High
Unreviewed
CVE-2022-31250
was published
Jul 21, 2022
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html...
Low
Unreviewed
CVE-2014-5030
was published
May 17, 2022
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user...
High
Unreviewed
CVE-2022-32450
was published
Jul 19, 2022
An issue existed within the path validation logic for symlinks. This issue was addressed with...
High
Unreviewed
CVE-2020-10003
was published
May 24, 2022
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local...
Moderate
Unreviewed
CVE-2015-5287
was published
May 17, 2022
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) -...
Low
Unreviewed
CVE-2015-4155
was published
May 17, 2022
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x...
Moderate
Unreviewed
CVE-2015-3436
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API