GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,128
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,024
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
18 advisories
Filter by severity
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2,...
Moderate
Unreviewed
CVE-2025-5468
was published
Aug 12, 2025
UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR...
Moderate
Unreviewed
CVE-2025-30485
was published
Apr 3, 2025
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling....
Moderate
Unreviewed
CVE-2025-24832
was published
Feb 28, 2025
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an...
Moderate
Unreviewed
CVE-2024-45418
was published
Feb 25, 2025
Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low...
Moderate
Unreviewed
CVE-2024-52542
was published
Dec 17, 2024
Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability....
Moderate
Unreviewed
CVE-2024-52537
was published
Dec 11, 2024
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated...
Moderate
Unreviewed
CVE-2023-20092
was published
Nov 15, 2024
A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated,...
Moderate
Unreviewed
CVE-2023-20091
was published
Nov 15, 2024
Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated...
Moderate
Unreviewed
CVE-2023-20093
was published
Nov 15, 2024
Arbitrary file overwrite during recovery due to improper soft link handling. The following...
Moderate
Unreviewed
CVE-2024-34014
was published
Nov 11, 2024
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a...
Moderate
Unreviewed
CVE-2024-0134
was published
Nov 5, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-39578
was published
Aug 31, 2024
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2024-27872
was published
Jul 30, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25952
was published
Mar 28, 2024
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25953
was published
Mar 28, 2024
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server...
Moderate
Unreviewed
CVE-2023-39246
was published
Nov 16, 2023
A symlink following vulnerability was found in Samba, where a user can create a symbolic link...
Moderate
Unreviewed
CVE-2022-3592
was published
Jan 12, 2023
Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote...
Moderate
Unreviewed
CVE-2021-32509
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API