GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,762
NuGet
678
pip
3,447
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
372 advisories
Filter by severity
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free...
High
Unreviewed
CVE-2022-36336
was published
Jul 31, 2022
A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows...
High
Unreviewed
CVE-2022-31250
was published
Jul 21, 2022
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user...
High
Unreviewed
CVE-2022-32450
was published
Jul 19, 2022
Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from...
High
Unreviewed
CVE-2022-2145
was published
Jun 29, 2022
Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure...
High
Unreviewed
CVE-2021-42056
was published
Jun 25, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31217
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31219
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31216
was published
Jun 16, 2022
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a...
High
Unreviewed
CVE-2022-31218
was published
Jun 16, 2022
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local,...
High
Unreviewed
CVE-2021-25261
was published
Jun 16, 2022
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local,...
High
Unreviewed
CVE-2022-28225
was published
Jun 16, 2022
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could...
High
Unreviewed
CVE-2022-30687
was published
May 28, 2022
A validation issue existed in the handling of symlinks and was addressed with improved validation...
High
Unreviewed
CVE-2022-26704
was published
May 27, 2022
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
High
Unreviewed
CVE-2013-4655
was published
May 24, 2022
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions...
High
Unreviewed
CVE-2019-1385
was published
May 24, 2022
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite...
High
Unreviewed
CVE-2021-41057
was published
May 24, 2022
Windows Installer Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-41379
was published
May 24, 2022
Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain...
High
Unreviewed
CVE-2021-36286
was published
May 24, 2022
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local...
High
Unreviewed
CVE-2021-1612
was published
May 24, 2022
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to...
High
Unreviewed
CVE-2021-31843
was published
May 24, 2022
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different...
High
Unreviewed
CVE-2021-41072
was published
May 24, 2022
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability This CVE ID is unique from...
High
Unreviewed
CVE-2021-36928
was published
May 24, 2022
Windows User Account Profile Picture Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-26426
was published
May 24, 2022
Windows Event Tracing Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021...
High
Unreviewed
CVE-2021-26425
was published
May 24, 2022
replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a...
High
Unreviewed
CVE-2021-36983
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API