GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
457 advisories
Filter by severity
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device...
Moderate
Unreviewed
CVE-1999-0783
was published
Apr 30, 2022
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack...
Moderate
Unreviewed
CVE-2004-1901
was published
Apr 29, 2022
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files...
Moderate
Unreviewed
CVE-2004-1603
was published
Apr 29, 2022
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations,...
Moderate
Unreviewed
CVE-2004-0689
was published
Apr 29, 2022
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a...
Moderate
Unreviewed
CVE-2003-1492
was published
Apr 29, 2022
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root,...
Moderate
Unreviewed
CVE-2003-0578
was published
Apr 29, 2022
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link...
Moderate
Unreviewed
CVE-2022-24372
was published
Apr 28, 2022
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink...
Moderate
Unreviewed
CVE-2012-1093
was published
Apr 23, 2022
Pacemaker before 1.1.6 configure script creates temporary files insecurely
Moderate
Unreviewed
CVE-2011-5271
was published
Apr 23, 2022
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2923
was published
Apr 22, 2022
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of...
Moderate
Unreviewed
CVE-2011-2924
was published
Apr 22, 2022
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
Moderate
Unreviewed
CVE-2010-4817
was published
Apr 21, 2022
The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via...
Moderate
Unreviewed
CVE-2010-0398
was published
Apr 21, 2022
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution....
Moderate
Unreviewed
CVE-2022-20068
was published
Apr 12, 2022
In connsyslogger, there is a possible symbolic link following due to improper link resolution....
Moderate
Unreviewed
CVE-2022-20050
was published
Mar 11, 2022
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink...
Moderate
Unreviewed
CVE-2021-44141
was published
Feb 22, 2022
Improper Link Resolution Before File Access in Jenkins Pipeline: Shared Groovy Libraries Plugin
Moderate
CVE-2022-25177
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps-global-lib
(Maven)
Feb 16, 2022
Improper Link Resolution Before File Access in Jenkins Pipeline: Groovy Plugin
Moderate
CVE-2022-25176
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Feb 16, 2022
Link Following in Jenkins Pipeline Multibranch Plugin
Moderate
CVE-2022-25179
was published
for
org.jenkins-ci.plugins.workflow:workflow-multibranch
(Maven)
Feb 16, 2022
Symlink Attack in kubectl cp
Moderate
CVE-2019-1002101
was published
for
k8s.io/kubernetes
(Go)
Feb 15, 2022
Symlink Attack in Libcontainer and Docker Engine
Moderate
CVE-2015-3627
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Mercurial Path Traversal/Link Following vulnerability
Moderate
CVE-2019-3902
was published
for
mercurial
(pip)
Feb 15, 2022
Directory Traversal in Docker
Moderate
CVE-2014-9358
was published
for
github.com/docker/docker
(Go)
Feb 15, 2022
Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer
Moderate
CVE-2020-26277
was published
for
github.com/datacharmer/dbdeployer
(Go)
Feb 12, 2022
Windows Cleanup Manager Elevation of Privilege Vulnerability.
Moderate
Unreviewed
CVE-2022-21838
was published
Jan 12, 2022
ProTip!
Advisories are also available from the
GraphQL API