GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
117 advisories
Filter by severity
A race condition in GitHub Enterprise Server was identified that could allow an attacker...
Moderate
Unreviewed
CVE-2023-46649
was published
Dec 21, 2023
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a...
Moderate
Unreviewed
CVE-2023-6803
was published
Dec 21, 2023
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating...
Moderate
Unreviewed
CVE-2022-45809
was published
Dec 19, 2023
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage...
Moderate
Unreviewed
CVE-2022-3700
was published
Oct 27, 2023
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2023-23520
was published
Feb 27, 2023
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to...
Moderate
Unreviewed
CVE-2021-35937
was published
Aug 26, 2022
A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race...
Moderate
Unreviewed
CVE-2022-1974
was published
Sep 1, 2022
This vulnerability allows physical attackers to execute arbitrary code on affected Tesla vehicles...
Moderate
Unreviewed
CVE-2022-3093
was published
Mar 29, 2023
In ion, there is a possible escalation of privilege due to improper locking. This could lead to...
Moderate
Unreviewed
CVE-2023-20623
was published
Mar 7, 2023
In adsp, there is a possible escalation of privilege due to a logic error. This could lead to...
Moderate
Unreviewed
CVE-2023-20620
was published
Mar 7, 2023
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client...
Moderate
Unreviewed
CVE-2020-13162
was published
May 24, 2022
DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead...
Moderate
Unreviewed
CVE-2022-33982
was published
Nov 15, 2022
DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after...
Moderate
Unreviewed
CVE-2022-30774
was published
Nov 15, 2022
Update description and links DMA transactions which are targeted at input buffers used for the...
Moderate
Unreviewed
CVE-2022-31243
was published
Nov 15, 2022
DMA transactions which are targeted at input buffers used for the software SMI handler used by...
Moderate
Unreviewed
CVE-2022-33907
was published
Nov 15, 2022
DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI...
Moderate
Unreviewed
CVE-2022-33906
was published
Nov 15, 2022
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in...
Moderate
Unreviewed
CVE-2018-16872
was published
May 13, 2022
TOCTOU Race Condition vulnerability in apport allows a local attacker to escalate privileges and...
Moderate
Unreviewed
CVE-2020-15702
was published
May 24, 2022
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all...
Moderate
Unreviewed
CVE-2022-23029
was published
Jan 26, 2022
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the Routing Protocol Daemon ...
Moderate
Unreviewed
CVE-2022-22225
was published
Oct 18, 2022
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd...
Moderate
Unreviewed
CVE-2022-22220
was published
Oct 18, 2022
In isp, there is a possible out of bounds write due to a race condition. This could lead to local...
Moderate
Unreviewed
CVE-2022-32638
was published
Jan 3, 2023
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows...
Moderate
Unreviewed
CVE-2017-11830
was published
May 13, 2022
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially...
Moderate
Unreviewed
CVE-2023-20523
was published
Jan 11, 2023
ProTip!
Advisories are also available from the
GraphQL API