GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
323 advisories
Filter by severity
In adsp, there is a possible escalation of privilege due to a logic error. This could lead to...
Moderate
Unreviewed
CVE-2023-20620
was published
Mar 7, 2023
In ion, there is a possible escalation of privilege due to improper locking. This could lead to...
Moderate
Unreviewed
CVE-2023-20623
was published
Mar 7, 2023
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection...
High
Unreviewed
CVE-2022-33257
was published
Mar 10, 2023
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle...
High
Unreviewed
CVE-2019-1065
was published
May 24, 2022
mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
High
CVE-2021-30465
was published
for
github.com/opencontainers/runc
(Go)
May 25, 2021
Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to...
High
Unreviewed
CVE-2019-11774
was published
May 24, 2022
Time-of-check Time-of-use (TOCTOU) Race Condition in chownr
Low
CVE-2017-18869
was published
for
chownr
(npm)
Feb 10, 2022
This vulnerability allows remote attackers to bypass authentication on affected installations of...
High
Unreviewed
CVE-2022-36980
was published
Mar 29, 2023
This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles...
Moderate
Unreviewed
CVE-2022-3093
was published
Mar 29, 2023
arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD...
High
Unreviewed
CVE-2021-29657
was published
May 24, 2022
Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10...
High
Unreviewed
CVE-2019-7307
was published
May 24, 2022
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race...
Moderate
Unreviewed
CVE-2022-1974
was published
Sep 1, 2022
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to...
Moderate
Unreviewed
CVE-2021-35937
was published
Aug 26, 2022
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Low
GHSA-f2wx-xjfw-xjv6
was published
for
topgrade
(Rust)
Jul 17, 2023
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2023-23520
was published
Feb 27, 2023
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests....
Low
Unreviewed
CVE-2023-5760
was published
Nov 8, 2023
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU)...
High
Unreviewed
CVE-2023-38041
was published
Oct 25, 2023
FoodCoopShop Server-Side Request Forgery vulnerability
High
CVE-2023-46725
was published
for
foodcoopshop/foodcoopshop
(Composer)
Nov 2, 2023
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage...
Moderate
Unreviewed
CVE-2022-3700
was published
Oct 27, 2023
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3...
High
Unreviewed
CVE-2022-3702
was published
Oct 27, 2023
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin...
High
Unreviewed
CVE-2022-3701
was published
Oct 27, 2023
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR...
Low
Unreviewed
CVE-2023-37867
was published
Nov 30, 2023
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in...
High
Unreviewed
CVE-2023-1295
was published
Jun 28, 2023
ProTip!
Advisories are also available from the
GraphQL API