GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
50 advisories
Filter by severity
A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This...
Low
Unreviewed
CVE-2024-10372
was published
Oct 25, 2024
Products for macOS enables a user logged on to the system to perform a denial-of-service attack,...
Moderate
Unreviewed
CVE-2024-6654
was published
Sep 27, 2024
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an...
Moderate
Unreviewed
CVE-2024-5742
was published
Jun 12, 2024
In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names...
Moderate
Unreviewed
CVE-2024-34490
was published
May 5, 2024
Jenkins temporary uploaded file created with insecure permissions
Low
CVE-2023-43498
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 20, 2023
Active Support Possibly Discloses Locally Encrypted Files
Low
CVE-2023-38037
was published
for
activesupport
(RubyGems)
Aug 23, 2023
Insecure temporary file in the installer for Zoom Rooms before version 5.15.0 may allow an...
High
Unreviewed
CVE-2023-34119
was published
Jul 11, 2023
Insecure Temporary File in HuTool
High
CVE-2023-33695
was published
for
cn.hutool:hutool-core
(Maven)
Jun 13, 2023
transformers has Insecure Temporary File
Moderate
CVE-2023-2800
was published
for
transformers
(pip)
May 18, 2023
Java Merge-sort Insecure Temporary File vulnerability
Moderate
CVE-2022-24913
was published
for
com.fasterxml.util:java-merge-sort
(Maven)
Jan 12, 2023
globalpom-utils has Insecure Temporary File
Critical
CVE-2018-25068
was published
for
com.anrisoftware.globalpom:globalpomutils
(Maven)
Jan 6, 2023
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This...
High
Unreviewed
CVE-2022-4817
was published
Dec 28, 2022
A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is...
Moderate
Unreviewed
CVE-2022-4641
was published
Dec 22, 2022
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this...
Moderate
Unreviewed
CVE-2022-3969
was published
Nov 13, 2022
ManyDesigns Portofino subject to creation of insecure temporary file
High
CVE-2022-3952
was published
for
com.manydesigns:portofino
(Maven)
Nov 11, 2022
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat...
High
Unreviewed
CVE-2013-4253
was published
Oct 19, 2022
ansible-runner 2.0.0 vulnerable to Race Condition
Moderate
CVE-2021-3702
was published
for
ansible-runner
(pip)
Aug 24, 2022
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
High
CVE-2022-27772
was published
for
org.springframework.boot:spring-boot
(Maven)
Jul 11, 2022
A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5,...
Low
Unreviewed
CVE-2021-25316
was published
May 24, 2022
A Insecure Temporary File vulnerability in the packaging of cyrus-sasl of openSUSE Factory allows...
High
Unreviewed
CVE-2020-8032
was published
May 24, 2022
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS,...
Moderate
Unreviewed
CVE-2020-8027
was published
May 24, 2022
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers...
Moderate
Unreviewed
CVE-2020-8030
was published
May 24, 2022
phpMyAdmin unsafely handles temporary files
High
CVE-2008-7252
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Insecure Temporary File in Jinja2
Moderate
CVE-2014-0012
was published
for
Jinja2
(pip)
May 17, 2022
RPLY Predictable Tmpfile Names Allows Cache Spoofing
Low
CVE-2014-1604
was published
for
RPLY
(pip)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API