GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
417 advisories
Filter by severity
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2022-47505
was published
Apr 21, 2023
Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion...
High
Unreviewed
CVE-2022-38604
was published
Apr 11, 2023
Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access...
High
Unreviewed
CVE-2023-25940
was published
Apr 4, 2023
There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An...
High
Unreviewed
CVE-2022-47188
was published
Apr 1, 2023
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete...
High
Unreviewed
CVE-2023-28892
was published
Mar 29, 2023
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the...
High
Unreviewed
CVE-2023-26088
was published
Mar 23, 2023
cloudflared's Installer has Local Privilege Escalation Vulnerability
High
CVE-2023-1314
was published
for
github.com/cloudflare/cloudflared
(Go)
Mar 21, 2023
A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow...
High
Unreviewed
CVE-2023-25145
was published
Mar 10, 2023
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a...
High
Unreviewed
CVE-2023-25146
was published
Mar 10, 2023
A security agent link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-25148
was published
Mar 10, 2023
Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the...
High
Unreviewed
CVE-2022-45697
was published
Feb 27, 2023
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user...
High
Unreviewed
CVE-2022-42292
was published
Feb 12, 2023
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following
High
CVE-2023-25152
was published
for
github.com/pterodactyl/wings
(Go)
Feb 8, 2023
Unsafe tar unpacking in HashiCorp go-slug
High
CVE-2020-29529
was published
for
github.com/hashicorp/go-slug
(Go)
Feb 6, 2023
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS Software could allow an...
High
Unreviewed
CVE-2023-20008
was published
Jan 20, 2023
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and...
High
Unreviewed
CVE-2022-45798
was published
Dec 24, 2022
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be...
High
Unreviewed
CVE-2022-45412
was published
Dec 22, 2022
A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical....
High
Unreviewed
CVE-2022-4563
was published
Dec 21, 2022
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended...
High
Unreviewed
CVE-2009-1143
was published
Nov 23, 2022
Local privilege escalation due to improper soft link handling. The following products are...
High
Unreviewed
CVE-2022-44747
was published
Nov 8, 2022
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
High
Unreviewed
CVE-2022-32905
was published
Nov 2, 2022
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as...
High
Unreviewed
CVE-2022-41973
was published
Oct 29, 2022
A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called...
High
Unreviewed
CVE-2022-31256
was published
Oct 26, 2022
Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by...
High
Unreviewed
CVE-2022-42725
was published
Oct 10, 2022
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security...
High
Unreviewed
CVE-2022-40710
was published
Sep 29, 2022
ProTip!
Advisories are also available from the
GraphQL API