GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,163 advisories
Filter by severity
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors...
High
Unreviewed
CVE-2002-2374
was published
Apr 30, 2022
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations,...
Moderate
Unreviewed
CVE-2004-0689
was published
Apr 29, 2022
Improper link resolution before file access ('link following') in Windows Installer allows an...
High
Unreviewed
CVE-2025-27727
was published
Apr 8, 2025
The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir...
Moderate
Unreviewed
CVE-2007-4652
was published
May 1, 2022
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary...
Moderate
Unreviewed
CVE-2008-1694
was published
May 1, 2022
policyd-weight 0.1.14 beta-16 and earlier allows local users to modify or delete arbitrary files...
Low
Unreviewed
CVE-2008-1569
was published
May 1, 2022
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to...
Moderate
Unreviewed
CVE-2008-2052
was published
May 1, 2022
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary...
Moderate
Unreviewed
CVE-2008-1684
was published
May 1, 2022
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote...
High
Unreviewed
CVE-2008-2311
was published
May 1, 2022
Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of...
High
Unreviewed
CVE-2008-4694
was published
May 17, 2022
An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall...
Moderate
Unreviewed
CVE-2025-23010
was published
Apr 10, 2025
fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on...
Low
Unreviewed
CVE-2010-0792
was published
May 2, 2022
The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users...
Moderate
Unreviewed
CVE-2009-1299
was published
May 2, 2022
Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on...
Low
Unreviewed
CVE-2010-0118
was published
May 2, 2022
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4...
Moderate
Unreviewed
CVE-2010-0787
was published
May 2, 2022
MySQL before 5.1.46 allows local users to delete the data and index files of another user's...
Low
Unreviewed
CVE-2010-1626
was published
May 13, 2022
emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary...
Low
Unreviewed
CVE-2010-2053
was published
May 17, 2022
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x...
Moderate
Unreviewed
CVE-2010-3847
was published
May 14, 2022
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary...
Moderate
Unreviewed
CVE-2010-3879
was published
May 13, 2022
The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330...
Moderate
Unreviewed
CVE-2011-1004
was published
May 17, 2022
The Debian GNU/Linux /etc/cron.d/php5 cron job for PHP 5.3.5 allows local users to delete...
Moderate
Unreviewed
CVE-2011-0441
was published
May 17, 2022
The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU...
Low
Unreviewed
CVE-2009-5079
was published
May 2, 2022
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*...
Low
Unreviewed
CVE-2009-5082
was published
May 2, 2022
The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib...
Low
Unreviewed
CVE-2009-5080
was published
May 2, 2022
The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl...
Low
Unreviewed
CVE-2009-5081
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API