GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      14 advisories
        Filter by severity
        
      
      
    
                    
                      A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-46705
                      
                      was published
                      Mar 17, 2022 
                    
                  
                    
                      A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-21945
                      
                      was published
                      Mar 17, 2022 
                    
                  
                    
                      A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3969
                      
                      was published
                      Nov 13, 2022 
                    
                  
                    
                      A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS,...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2020-8027
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4641
                      
                      was published
                      Dec 22, 2022 
                    
                  
                    
                      A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2020-8030
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-34490
                      
                      was published
                      May 5, 2024 
                    
                  
                    
                      Products for macOS enables a user logged on to the system to perform a denial-of-service attack,...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-6654
                      
                      was published
                      Sep 27, 2024 
                    
                  
                    
                      A vulnerability was found in GNU Nano that allows a possible privilege escalation through an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-5742
                      
                      was published
                      Jun 12, 2024 
                    
                  
                    
                      A privacy issue was addressed with improved handling of temporary files. This issue is fixed in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-23287
                      
                      was published
                      Mar 8, 2024 
                    
                  
                    
                      Previously Firefox for macOS and Linux would download temporary files to a user-specific...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-26386
                      
                      was published
                      Dec 22, 2022 
                    
                  
                    
                      It was found that rhnsd PID files are created as world-writable that allows local attackers to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-7560
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-20147
                      
                      was published
                      Sep 21, 2022 
                    
                  
                    
                      bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61659
                      
                      was published
                      Sep 29, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API