GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,053 advisories
Filter by severity
** DISPUTED ** init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via...
Moderate
Unreviewed
CVE-2008-4996
was published
May 17, 2022
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files...
High
Unreviewed
CVE-2024-57728
was published
Jan 16, 2025
Windows Event Tracing Denial of Service Vulnerability
Moderate
Unreviewed
CVE-2025-21274
was published
Jan 14, 2025
Windows Installer Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21331
was published
Jan 14, 2025
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25953
was published
Mar 28, 2024
Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink)...
Moderate
Unreviewed
CVE-2024-25952
was published
Mar 28, 2024
Microsoft Office Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49059
was published
Dec 12, 2024
RenderDoc through 1.26 allows local privilege escalation via a symlink attack.
High
Unreviewed
CVE-2023-33865
was published
Jun 7, 2023
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-44211
was published
Dec 20, 2024
A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2024-52050
was published
Dec 31, 2024
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability...
High
Unreviewed
CVE-2024-13043
was published
Dec 30, 2024
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2024-12753
was published
Dec 30, 2024
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local...
Moderate
Unreviewed
CVE-2024-12754
was published
Dec 30, 2024
gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.
Moderate
Unreviewed
CVE-2024-56074
was published
Dec 15, 2024
Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2024-12552
was published
Dec 14, 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia...
High
Unreviewed
CVE-2024-44132
was published
Sep 17, 2024
WmsRepair Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49107
was published
Dec 12, 2024
Link Following in github.com/containers/common
Moderate
CVE-2024-9341
was published
for
github.com/containers/common
(Go)
Oct 1, 2024
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack...
Critical
Unreviewed
CVE-2024-37143
was published
Dec 10, 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma...
High
Unreviewed
CVE-2024-23285
was published
Mar 8, 2024
A link following vulnerability has been reported to affect Qsync Central. If exploited, the...
Moderate
Unreviewed
CVE-2024-50404
was published
Dec 6, 2024
A link following vulnerability has been reported to affect several QNAP operating system versions...
High
Unreviewed
CVE-2024-53691
was published
Dec 6, 2024
runc AppArmor bypass with symlinked /proc
Moderate
CVE-2023-28642
was published
for
github.com/opencontainers/runc
(Go)
Mar 30, 2023
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in...
High
Unreviewed
CVE-2019-12749
was published
May 24, 2022
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1,...
High
Unreviewed
CVE-2023-42942
was published
Feb 21, 2024
ProTip!
Advisories are also available from the
GraphQL API