GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,488 advisories
Filter by severity
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2026-19909
was published
Aug 14, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock...
Moderate
Unreviewed
CVE-2026-63426
was published
Aug 13, 2026
During an internal security assessment, an improper link following vulnerability was identified...
High
Unreviewed
CVE-2026-15994
was published
Aug 13, 2026
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage...
Moderate
Unreviewed
CVE-2026-12036
was published
Aug 13, 2026
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Moderate
CVE-2026-55086
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the...
High
Unreviewed
CVE-2026-73613
was published
Aug 13, 2026
An improper link resolution before file access vulnerability exists in the Palo Alto Networks...
Low
Unreviewed
CVE-2026-0291
was published
Aug 13, 2026
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
High
CVE-2026-55074
was published
for
ansible-jailexec
(pip)
Aug 12, 2026
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an...
Moderate
Unreviewed
CVE-2026-65680
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows Container Isolation FS...
Moderate
Unreviewed
CVE-2026-72971
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows Management Services...
Moderate
Unreviewed
CVE-2026-70348
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an...
High
Unreviewed
CVE-2026-62812
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows User Profile Service...
High
Unreviewed
CVE-2026-62832
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an...
High
Unreviewed
CVE-2026-62807
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an...
High
Unreviewed
CVE-2026-62803
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an...
High
Unreviewed
CVE-2026-62776
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows DHCP Server allows an...
High
Unreviewed
CVE-2026-62761
was published
Aug 11, 2026
Improper link resolution before file access ('link following') in Windows Accessibility...
High
Unreviewed
CVE-2026-61358
was published
Aug 11, 2026
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops...
High
Unreviewed
CVE-2026-72694
was published
Aug 11, 2026
The affected TP-Link Aginet devices do not properly validate symbolic links created on external...
Moderate
Unreviewed
CVE-2025-30240
was published
Aug 11, 2026
A flaw was found in libvirt. A local attacker, specifically a process running as the confined ...
High
Unreviewed
CVE-2026-63622
was published
Aug 10, 2026
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the...
High
Unreviewed
CVE-2026-71964
was published
Aug 10, 2026
tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder:...
High
Unreviewed
CVE-2026-70622
was published
Aug 10, 2026
Jenkins FilePath.untarFrom() (all versions) validates symlink destinations but not targets,...
Critical
Unreviewed
CVE-2026-19429
was published
Aug 10, 2026
go-git: Worktree operations may follow symlinks
High
CVE-2026-71556
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
ProTip!
Advisories are also available from the
GraphQL API