GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
78 advisories
Filter by severity
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform...
High
Unreviewed
CVE-2026-20204
was published
Apr 15, 2026
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
Moderate
GHSA-5qvp-pr9f-2g2v
was published
for
poetry-plugin-tweak-dependencies-version
(pip)
Apr 1, 2026
A vulnerability was detected in Enter Software Iperius Backup bis 8.7.3. Affected is an unknown...
High
Unreviewed
CVE-2026-4822
was published
Mar 25, 2026
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Moderate
CVE-2026-25645
was published
for
requests
(pip)
Mar 25, 2026
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-20651
was published
Mar 25, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create...
High
Unreviewed
CVE-2026-25701
was published
Feb 25, 2026
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-20618
was published
Feb 12, 2026
A logging issue was addressed with improved data redaction. This issue is fixed in watchOS 26.3,...
High
Unreviewed
CVE-2026-20649
was published
Feb 12, 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Standard
Installer (SFX)
on...
Moderate
Unreviewed
CVE-2025-14614
was published
Jan 7, 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Pro
Installer (SFX)
on Windows...
Moderate
Unreviewed
CVE-2025-14612
was published
Jan 7, 2026
Robocode has an insecure temporary file creation vulnerability in the AutoExtract component
Critical
CVE-2025-14307
was published
for
net.sf.robocode:robocode.battle
(Maven)
Dec 9, 2025
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
Moderate
CVE-2025-66625
was published
for
Umbraco.Cms
(NuGet)
Dec 9, 2025
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure...
High
Unreviewed
CVE-2025-46369
was published
Nov 13, 2025
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure...
Moderate
Unreviewed
CVE-2025-46368
was published
Nov 13, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has...
Moderate
Unreviewed
CVE-2025-61659
was published
Sep 29, 2025
A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function...
Low
Unreviewed
CVE-2025-9474
was published
Aug 26, 2025
pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.
Low
Unreviewed
CVE-2015-0849
was published
Jun 27, 2025
Insecure Temporary File usage in github.com/golang/glog
Moderate
CVE-2024-45339
was published
for
github.com/golang/glog
(Go)
Jan 28, 2025
Insecure creation of temporary files allows local users on systems with non-default...
High
Unreviewed
CVE-2024-49506
was published
Nov 13, 2024
A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This...
Low
Unreviewed
CVE-2024-10372
was published
Oct 25, 2024
Products for macOS enables a user logged on to the system to perform a denial-of-service attack,...
Moderate
Unreviewed
CVE-2024-6654
was published
Sep 27, 2024
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an...
Moderate
Unreviewed
CVE-2024-5742
was published
Jun 12, 2024
In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names...
Moderate
Unreviewed
CVE-2024-34490
was published
May 5, 2024
ProTip!
Advisories are also available from the
GraphQL API