GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,359
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,554
Pub
12
RubyGems
1,013
Rust
1,205
Swift
51
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
OpenClaw gateway agents.files symlink escape allowed out-of-workspace file read/write
Critical
CVE-2026-32013
was published
for
openclaw
(npm)
Mar 2, 2026
A link following vulnerability has been reported to affect several QNAP operating system versions...
Critical
Unreviewed
CVE-2025-66277
was published
Feb 11, 2026
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including...
Critical
Unreviewed
CVE-2025-69430
was published
Feb 3, 2026
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following....
Critical
Unreviewed
CVE-2025-69431
was published
Feb 3, 2026
Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0...
Critical
Unreviewed
CVE-2025-11462
was published
Oct 7, 2025
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7...
Critical
Unreviewed
CVE-2025-43220
was published
Jul 30, 2025
Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh...
Critical
Unreviewed
CVE-2025-52936
was published
Jun 23, 2025
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-30457
was published
Apr 1, 2025
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24278
was published
Apr 1, 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia...
Critical
Unreviewed
CVE-2025-24242
was published
Apr 1, 2025
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack...
Critical
Unreviewed
CVE-2024-37143
was published
Dec 10, 2024
qdrant input validation failure
Critical
CVE-2024-3829
was published
for
qdrant-client
(pip)
Jun 3, 2024
Froxlor Improper Input Validation vulnerability
Critical
CVE-2023-6069
was published
for
froxlor/froxlor
(Composer)
Nov 10, 2023
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for...
Critical
Unreviewed
CVE-2023-39107
was published
Aug 4, 2023
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system
Critical
CVE-2023-25168
was published
for
github.com/pterodactyl/wings
(Go)
Feb 10, 2023
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code...
Critical
Unreviewed
CVE-2021-3942
was published
Dec 12, 2022
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission...
Critical
Unreviewed
CVE-2022-23144
was published
Sep 25, 2022
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points...
Critical
Unreviewed
CVE-2022-34960
was published
Aug 26, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21686
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21691
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21695
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to...
Critical
Unreviewed
CVE-2021-38570
was published
May 24, 2022
Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2...
Critical
Unreviewed
CVE-2020-25989
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API