GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
184 advisories
Filter by severity
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced...
High
Unreviewed
CVE-2018-8584
was published
May 13, 2022
An ability to process crash dumps under root privileges and inappropriate symlinks handling could...
High
Unreviewed
CVE-2017-15404
was published
May 13, 2022
A remote code execution vulnerability in the Android media framework (libstagefright). Product:...
High
Unreviewed
CVE-2017-0756
was published
May 13, 2022
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious...
High
Unreviewed
CVE-2017-0331
was published
May 13, 2022
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious...
High
Unreviewed
CVE-2017-0411
was published
May 13, 2022
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious...
High
Unreviewed
CVE-2017-0412
was published
May 13, 2022
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a...
High
Unreviewed
CVE-2019-7347
was published
May 13, 2022
VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600...
High
Unreviewed
CVE-2019-5519
was published
May 13, 2022
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a...
High
Unreviewed
CVE-2021-42835
was published
Dec 9, 2021
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV...
High
Unreviewed
CVE-2019-0836
was published
May 13, 2022
Dell BIOS contains a race condition vulnerability. A local attacker could exploit this...
High
Unreviewed
CVE-2022-26859
was published
Sep 7, 2022
An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged...
High
Unreviewed
CVE-2022-34830
was published
Nov 23, 2022
When installing an add-on, Firefox verified the signature before prompting the user; but while...
High
Unreviewed
CVE-2022-26387
was published
Dec 22, 2022
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service...
High
Unreviewed
CVE-2022-44651
was published
Dec 12, 2022
Possible memory corruption due to Improper handling of hypervisor unmap operations for concurrent...
High
Unreviewed
CVE-2021-1921
was published
May 24, 2022
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility...
High
Unreviewed
CVE-2021-34788
was published
May 24, 2022
All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a...
High
Unreviewed
CVE-2021-34413
was published
May 24, 2022
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks...
High
Unreviewed
CVE-2021-3054
was published
May 24, 2022
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone....
High
Unreviewed
CVE-2021-22369
was published
May 24, 2022
Race condition in Apache Tomcat
High
CVE-2022-23181
was published
for
org.apache.tomcat:tomcat
(Maven)
Feb 1, 2022
While waiting for a response to a callback or listener request, non-secure clients can change...
High
Unreviewed
CVE-2020-11298
was published
May 24, 2022
Time-of-check time-of-use race condition While processing partition entries due to newly created...
High
Unreviewed
CVE-2020-11233
was published
May 24, 2022
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race...
High
Unreviewed
CVE-2021-21539
was published
May 24, 2022
This vulnerability allows local attackers to escalate privileges on affected installations of...
High
Unreviewed
CVE-2021-31422
was published
May 24, 2022
A TOCTOU vulnerability exists in madCodeHook before 2020-07-16 that allows local attackers to...
High
Unreviewed
CVE-2020-14418
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API