GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,109
Maven
5,000+
npm
3,764
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
887
Swift
37
Unreviewed advisories
All unreviewed
5,000+
455 advisories
Filter by severity
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an...
Moderate
Unreviewed
CVE-2024-5742
was published
Jun 12, 2024
Microsoft Azure File Sync Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-35253
was published
Jun 11, 2024
Windows Container Manager Service Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-30076
was published
Jun 11, 2024
Windows Themes Denial of Service Vulnerability
Moderate
Unreviewed
CVE-2024-30065
was published
Jun 11, 2024
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service Damage...
Moderate
Unreviewed
CVE-2024-36306
was published
Jun 11, 2024
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-27885
was published
Jun 10, 2024
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows...
Moderate
Unreviewed
CVE-2024-4712
was published
May 14, 2024
An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows...
Moderate
Unreviewed
CVE-2024-3037
was published
May 14, 2024
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the...
Moderate
Unreviewed
CVE-2024-31952
was published
May 14, 2024
NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2023-34283
was published
May 3, 2024
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client...
Moderate
Unreviewed
CVE-2023-41971
was published
May 2, 2024
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25953
was published
Mar 28, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25952
was published
Mar 28, 2024
Podman affected by CVE-2024-1753 container escape at build time
Moderate
CVE-2024-1753
was published
for
github.com/containers/podman/v4
(Go)
Mar 28, 2024
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce...
Moderate
Unreviewed
CVE-2024-0068
was published
Feb 29, 2024
Microsoft Azure File Sync Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-21397
was published
Feb 13, 2024
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount...
Moderate
Unreviewed
CVE-2023-32454
was published
Feb 6, 2024
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on...
Moderate
Unreviewed
CVE-2023-32474
was published
Feb 6, 2024
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce...
Moderate
Unreviewed
CVE-2023-6335
was published
Jan 16, 2024
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan...
Moderate
Unreviewed
CVE-2023-51654
was published
Dec 26, 2023
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry...
Moderate
Unreviewed
CVE-2023-28871
was published
Dec 9, 2023
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents...
Moderate
Unreviewed
CVE-2023-28869
was published
Dec 9, 2023
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server...
Moderate
Unreviewed
CVE-2023-39246
was published
Nov 16, 2023
Jenkins CloudBees CD Plugin vulnerable to arbitrary file read
Moderate
CVE-2023-46655
was published
for
org.jenkins-ci.plugins:electricflow
(Maven)
Oct 25, 2023
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2023-41968
was published
Sep 27, 2023
ProTip!
Advisories are also available from the
GraphQL API