GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
503 advisories
Filter by severity
This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated...
Moderate
Unreviewed
CVE-2024-25103
was published
Mar 6, 2024
electron-builder's NSIS installer - execute arbitrary code on the target machine (Windows only)
High
CVE-2024-27303
was published
for
app-builder-lib
(npm)
Mar 4, 2024
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to...
High
Unreviewed
CVE-2024-24697
was published
Feb 14, 2024
PanelSwWix4.Sdk .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
High
GHSA-8v28-3g86-chj5
was published
for
PanelSwWix4.Sdk
(NuGet)
Feb 8, 2024
Panel::Software Customized WiX .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
High
GHSA-259p-rvjx-ffwg
was published
for
PanelSW.Custom.WiX
(NuGet)
Feb 8, 2024
WiX Toolset's .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges
High
CVE-2024-24810
was published
for
wix
(NuGet)
Feb 8, 2024
Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a...
High
Unreviewed
CVE-2024-23304
was published
Feb 6, 2024
Yarn untrusted search path vulnerability
High
CVE-2021-4435
was published
for
yarn
(npm)
Feb 4, 2024
Untrusted search path under some conditions on Windows allows arbitrary code execution
High
CVE-2024-22190
was published
for
GitPython
(pip)
Jan 10, 2024
Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-21325
was published
Jan 9, 2024
Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation...
High
Unreviewed
CVE-2023-48670
was published
Dec 22, 2023
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for...
High
Unreviewed
CVE-2023-43586
was published
Dec 14, 2023
Multiple components of Iconics SCADA Suite are prone to a Phantom DLL loading vulnerability. This...
Moderate
Unreviewed
CVE-2023-6061
was published
Dec 8, 2023
Apache Hadoop allows local user to gain root privileges
High
CVE-2023-26031
was published
for
org.apache.hadoop:hadoop-yarn-project
(Maven)
Nov 16, 2023
Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged...
Low
Unreviewed
CVE-2023-39202
was published
Nov 15, 2023
A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to...
High
Unreviewed
CVE-2023-41840
was published
Nov 14, 2023
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the...
High
Unreviewed
CVE-2021-26738
was published
Oct 23, 2023
Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to...
Moderate
Unreviewed
CVE-2023-39201
was published
Sep 12, 2023
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
High
Unreviewed
CVE-2023-4736
was published
Sep 2, 2023
GitPython untrusted search path on Windows systems leading to arbitrary code execution
High
CVE-2023-40590
was published
for
gitpython
(pip)
Aug 29, 2023
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed...
High
Unreviewed
CVE-2023-41105
was published
Aug 23, 2023
Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3...
High
Unreviewed
CVE-2022-43456
was published
Aug 11, 2023
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are...
Moderate
Unreviewed
CVE-2023-29299
was published
Aug 10, 2023
Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated...
Moderate
Unreviewed
CVE-2023-39212
was published
Aug 9, 2023
Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may...
High
Unreviewed
CVE-2023-36540
was published
Aug 8, 2023
ProTip!
Advisories are also available from the
GraphQL API