GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,047 advisories
Filter by severity
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on...
Moderate
Unreviewed
CVE-2023-32474
was published
Feb 6, 2024
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote...
High
Unreviewed
CVE-2023-7216
was published
Feb 5, 2024
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One -...
High
Unreviewed
CVE-2023-52338
was published
Jan 23, 2024
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52091
was published
Jan 23, 2024
A security agent link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52092
was published
Jan 23, 2024
A security agent link following vulnerability in Trend Micro Apex One could allow a local...
High
Unreviewed
CVE-2023-52090
was published
Jan 23, 2024
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local...
High
Unreviewed
CVE-2023-52094
was published
Jan 23, 2024
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47192
was published
Jan 23, 2024
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce...
High
Unreviewed
CVE-2023-6336
was published
Jan 16, 2024
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce...
Moderate
Unreviewed
CVE-2023-6335
was published
Jan 16, 2024
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can...
High
Unreviewed
CVE-2023-42137
was published
Jan 15, 2024
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0...
High
Unreviewed
CVE-2023-31003
was published
Jan 11, 2024
Visual Studio Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-20656
was published
Jan 9, 2024
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January...
High
Unreviewed
CVE-2024-0206
was published
Jan 9, 2024
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan...
Moderate
Unreviewed
CVE-2023-51654
was published
Dec 26, 2023
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL...
High
Unreviewed
CVE-2023-28872
was published
Dec 25, 2023
Buildkite Elastic CI for AWS symbolic link following vulnerability
High
CVE-2023-43116
was published
for
github.com/buildkite/elastic-ci-stack-for-aws/v6
(Go)
Dec 22, 2023
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents...
Moderate
Unreviewed
CVE-2023-28869
was published
Dec 9, 2023
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry...
Moderate
Unreviewed
CVE-2023-28871
was published
Dec 9, 2023
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete...
High
Unreviewed
CVE-2023-28868
was published
Dec 9, 2023
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server...
Moderate
Unreviewed
CVE-2023-39246
was published
Nov 16, 2023
Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to...
High
Unreviewed
CVE-2023-43590
was published
Nov 15, 2023
Froxlor Improper Input Validation vulnerability
Critical
CVE-2023-6069
was published
for
froxlor/froxlor
(Composer)
Nov 10, 2023
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary...
High
Unreviewed
CVE-2020-28407
was published
Nov 3, 2023
HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
Low
CVE-2023-5834
was published
for
github.com/hashicorp/vagrant
(Go)
Oct 28, 2023
ProTip!
Advisories are also available from the
GraphQL API