GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,163 advisories
Filter by severity
Improper link resolution before file access ('link following') in Xbox allows an authorized...
High
Unreviewed
CVE-2025-55245
was published
Sep 9, 2025
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU)...
High
Unreviewed
CVE-2025-55317
was published
Sep 9, 2025
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local...
High
Unreviewed
CVE-2025-49156
was published
Jun 17, 2025
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a...
High
Unreviewed
CVE-2025-49157
was published
Jun 17, 2025
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
Low
Unreviewed
CVE-2025-55188
was published
Aug 8, 2025
Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link...
Moderate
Unreviewed
CVE-2025-43726
was published
Sep 2, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2024-54554
was published
Aug 29, 2025
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise...
High
Unreviewed
CVE-2024-10007
was published
Nov 7, 2024
n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
Moderate
CVE-2025-57749
was published
for
n8n
(npm)
Aug 20, 2025
AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2025-8612
was published
Aug 20, 2025
CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that...
High
Unreviewed
CVE-2025-5296
was published
Aug 18, 2025
A potential security vulnerability has been identified in the HPAudioAnalytics service included...
Moderate
Unreviewed
CVE-2025-43490
was published
Aug 15, 2025
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-42125
was published
May 3, 2024
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the...
Moderate
Unreviewed
CVE-2025-0913
was published
Jun 11, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
Moderate
Unreviewed
CVE-2011-4116
was published
Apr 22, 2022
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7...
Critical
Unreviewed
CVE-2025-43220
was published
Jul 30, 2025
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in...
Moderate
Unreviewed
CVE-2025-43252
was published
Jul 30, 2025
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an...
High
Unreviewed
CVE-2025-36611
was published
Jul 30, 2025
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's...
High
Unreviewed
CVE-2025-1079
was published
May 12, 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook,...
High
Unreviewed
CVE-2025-23267
was published
Jul 17, 2025
An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to...
High
Unreviewed
CVE-2025-7012
was published
Jul 13, 2025
Improper link resolution before file access ('link following') in Visual Studio allows an...
High
Unreviewed
CVE-2025-49739
was published
Jul 8, 2025
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an...
High
Unreviewed
CVE-2025-49738
was published
Jul 8, 2025
ProTip!
Advisories are also available from the
GraphQL API