GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
162 advisories
Filter by severity
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to...
Low
Unreviewed
CVE-2010-3691
was published
May 13, 2022
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink...
Low
Unreviewed
CVE-2011-1072
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to...
Low
Unreviewed
CVE-2011-0702
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to...
Low
Unreviewed
CVE-2011-1031
was published
May 13, 2022
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a...
Low
Unreviewed
CVE-2014-7206
was published
May 13, 2022
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2011-1144
was published
May 13, 2022
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to...
Low
Unreviewed
CVE-2011-4028
was published
May 13, 2022
Directory exposure in jetty
Low
CVE-2021-28163
was published
for
org.eclipse.jetty:jetty-deploy
(Maven)
Apr 6, 2021
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2...
Low
Unreviewed
CVE-2015-0794
was published
May 13, 2022
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to...
Low
Unreviewed
CVE-2014-5459
was published
May 13, 2022
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server...
Low
Unreviewed
CVE-2020-8013
was published
May 24, 2022
systemd, when updating file permissions, allows local users to change the permissions and SELinux...
Low
Unreviewed
CVE-2013-4392
was published
May 13, 2022
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3...
Low
Unreviewed
CVE-2013-4969
was published
May 13, 2022
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite...
Low
Unreviewed
CVE-2009-5044
was published
May 3, 2022
pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary...
Low
Unreviewed
CVE-2011-0007
was published
May 3, 2022
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local...
Low
Unreviewed
CVE-2011-0012
was published
May 3, 2022
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite...
Low
Unreviewed
CVE-2005-3011
was published
May 3, 2022
GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in...
Low
Unreviewed
CVE-2010-1160
was published
May 2, 2022
Certain patch-installation scripts in Oracle Solaris allow local users to append data to...
Low
Unreviewed
CVE-2010-1183
was published
May 2, 2022
fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on...
Low
Unreviewed
CVE-2010-0792
was published
May 2, 2022
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an...
Low
Unreviewed
CVE-2010-0789
was published
May 2, 2022
Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete...
Low
Unreviewed
CVE-2010-0546
was published
May 2, 2022
The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite...
Low
Unreviewed
CVE-2009-5007
was published
May 2, 2022
Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on...
Low
Unreviewed
CVE-2010-0118
was published
May 2, 2022
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib...
Low
Unreviewed
CVE-2009-5080
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API