GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
33 advisories
Filter by severity
Jenkins temporary uploaded file created with insecure permissions
Low
CVE-2023-43498
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Sep 20, 2023
Active Support Possibly Discloses Locally Encrypted Files
Low
CVE-2023-38037
was published
for
activesupport
(RubyGems)
Aug 23, 2023
Insecure Temporary File in HuTool
High
CVE-2023-33695
was published
for
cn.hutool:hutool-core
(Maven)
Jun 13, 2023
transformers has Insecure Temporary File
Moderate
CVE-2023-2800
was published
for
transformers
(pip)
May 18, 2023
Java Merge-sort Insecure Temporary File vulnerability
Moderate
CVE-2022-24913
was published
for
com.fasterxml.util:java-merge-sort
(Maven)
Jan 12, 2023
globalpom-utils has Insecure Temporary File
Critical
CVE-2018-25068
was published
for
com.anrisoftware.globalpom:globalpomutils
(Maven)
Jan 6, 2023
ManyDesigns Portofino subject to creation of insecure temporary file
High
CVE-2022-3952
was published
for
com.manydesigns:portofino
(Maven)
Nov 11, 2022
ansible-runner 2.0.0 vulnerable to Race Condition
Moderate
CVE-2021-3702
was published
for
ansible-runner
(pip)
Aug 24, 2022
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
High
CVE-2022-27772
was published
for
org.springframework.boot:spring-boot
(Maven)
Jul 11, 2022
phpMyAdmin unsafely handles temporary files
High
CVE-2008-7252
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Insecure Temporary File in Jinja2
Moderate
CVE-2014-0012
was published
for
Jinja2
(pip)
May 17, 2022
RPLY Predictable Tmpfile Names Allows Cache Spoofing
Low
CVE-2014-1604
was published
for
RPLY
(pip)
May 17, 2022
Puppet uses predictable filenames, allowing arbitrary file overwrite
Moderate
CVE-2012-1906
was published
for
puppet
(RubyGems)
May 14, 2022
instack-undercloud vulnerable to symlink attack on tmp files
Moderate
CVE-2017-7549
was published
for
instack-undercloud
(pip)
May 13, 2022
ruby_parser allows local users to overwrite arbitrary files via symlink attack on temporary file with predictable name
Low
CVE-2013-0162
was published
for
ruby_parser
(RubyGems)
May 5, 2022
Hadoop symlink vulnerability
High
CVE-2012-2945
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Apr 23, 2022
Insecure Temporary File in SWHKD
Critical
CVE-2022-27815
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Mar 31, 2022
Use of insecure temporary file in Horovod
High
CVE-2022-0315
was published
for
horovod
(pip)
Mar 29, 2022
Temporary Directory Hijacking Vulnerability in Keycloak
High
CVE-2021-20202
was published
for
org.keycloak:keycloak-core
(Maven)
Mar 18, 2022
Hub Package Arbitrary File Overwrite
Moderate
CVE-2014-0177
was published
for
github.com/github/hub
(RubyGems)
Feb 15, 2022
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Moderate
CVE-2020-10744
was published
for
ansible
(pip)
Feb 9, 2022
Insecure temporary file used in com.squareup:connect
Low
CVE-2021-23331
was published
for
com.squareup:connect
(Maven)
Jun 16, 2021
Creation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala code
Moderate
CVE-2021-21430
was published
for
org.openapitools:openapi-generator
(Maven)
May 11, 2021
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator
Critical
CVE-2021-21428
was published
for
org.openapitools:openapi-generator-online
(Maven)
May 11, 2021
ProTip!
Advisories are also available from the
GraphQL API