GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,163 advisories
Filter by severity
The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a...
Low
Unreviewed
CVE-2011-1144
was published
May 13, 2022
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a...
Low
Unreviewed
CVE-2014-7206
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to...
Low
Unreviewed
CVE-2011-1031
was published
May 13, 2022
The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to...
Low
Unreviewed
CVE-2011-0702
was published
May 13, 2022
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and...
High
Unreviewed
CVE-2021-35938
was published
Aug 26, 2022
The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink...
Low
Unreviewed
CVE-2011-1072
was published
May 13, 2022
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to...
Low
Unreviewed
CVE-2010-3691
was published
May 13, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1...
High
Unreviewed
CVE-2018-1834
was published
May 13, 2022
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha,...
Moderate
Unreviewed
CVE-2008-7247
was published
May 13, 2022
The main function in android_main.cpp in thermald allows local users to write to arbitrary files...
Moderate
Unreviewed
CVE-2014-2312
was published
May 13, 2022
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only...
High
Unreviewed
CVE-2021-35939
was published
Aug 27, 2022
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with...
Moderate
Unreviewed
CVE-2021-28153
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could...
High
Unreviewed
CVE-2018-1781
was published
May 13, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could...
High
Unreviewed
CVE-2018-1780
was published
May 13, 2022
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to...
Moderate
Unreviewed
CVE-2018-17955
was published
May 13, 2022
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4...
Critical
Unreviewed
CVE-2017-1002101
was published
May 13, 2022
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A...
High
Unreviewed
CVE-2016-9602
was published
May 13, 2022
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when...
High
Unreviewed
CVE-2016-8641
was published
May 13, 2022
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure...
Moderate
Unreviewed
CVE-2016-9595
was published
May 13, 2022
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service...
High
Unreviewed
CVE-2015-0796
was published
May 13, 2022
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10...
Moderate
Unreviewed
CVE-2017-2390
was published
May 13, 2022
An issue existed within the path validation logic for symlinks. This issue was addressed with...
High
Unreviewed
CVE-2020-9900
was published
May 24, 2022
An issue existed within the path validation logic for symlinks. This issue was addressed with...
High
Unreviewed
CVE-2020-9901
was published
May 24, 2022
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10...
High
Unreviewed
CVE-2017-6981
was published
May 13, 2022
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is...
Moderate
Unreviewed
CVE-2018-6198
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API