GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
184 advisories
Filter by severity
The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes...
High
Unreviewed
CVE-2022-4149
was published
Jun 15, 2023
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products,...
High
Unreviewed
CVE-2022-31640
was published
Jun 14, 2023
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP...
High
Unreviewed
CVE-2022-43778
was published
Jun 12, 2023
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script...
High
Unreviewed
CVE-2023-25394
was published
May 17, 2023
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read...
High
Unreviewed
CVE-2021-26356
was published
May 9, 2023
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux...
High
Unreviewed
CVE-2021-33632
was published
Mar 25, 2024
Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to...
High
Unreviewed
CVE-2023-32282
was published
Mar 14, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS...
High
Unreviewed
CVE-2022-48618
was published
Jan 9, 2024
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation...
High
Unreviewed
CVE-2022-47631
was published
Sep 15, 2023
Memory corruption in Trusted Execution Environment while deinitializing an object used for...
High
Unreviewed
CVE-2023-33046
was published
Feb 6, 2024
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated,...
High
Unreviewed
CVE-2023-20135
was published
Sep 13, 2023
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of...
High
Unreviewed
CVE-2023-2007
was published
Apr 25, 2023
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly...
High
Unreviewed
CVE-2020-1337
was published
May 24, 2022
Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability
High
CVE-2023-43741
was published
for
github.com/buildkite/elastic-ci-stack-for-aws/v6
(Go)
Dec 22, 2023
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in...
High
Unreviewed
CVE-2023-1295
was published
Jun 28, 2023
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3...
High
Unreviewed
CVE-2022-3702
was published
Oct 27, 2023
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin...
High
Unreviewed
CVE-2022-3701
was published
Oct 27, 2023
FoodCoopShop Server-Side Request Forgery vulnerability
High
CVE-2023-46725
was published
for
foodcoopshop/foodcoopshop
(Composer)
Nov 2, 2023
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU)...
High
Unreviewed
CVE-2023-38041
was published
Oct 25, 2023
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10...
High
Unreviewed
CVE-2019-7307
was published
May 24, 2022
arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD...
High
Unreviewed
CVE-2021-29657
was published
May 24, 2022
This vulnerability allows remote attackers to bypass authentication on affected installations of...
High
Unreviewed
CVE-2022-36980
was published
Mar 29, 2023
Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to...
High
Unreviewed
CVE-2019-11774
was published
May 24, 2022
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
High
CVE-2021-30465
was published
for
github.com/opencontainers/runc
(Go)
May 25, 2021
ProTip!
Advisories are also available from the
GraphQL API