GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,154
Erlang
30
GitHub Actions
19
Go
1,966
Maven
5,000+
npm
3,694
NuGet
652
pip
3,311
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
311 advisories
Filter by severity
NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system
Moderate
CVE-2024-0133
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Oct 29, 2024
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Critical
CVE-2024-0132
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Oct 29, 2024
Waitress has request processing race condition in HTTP pipelining with invalid first request
Critical
CVE-2024-49768
was published
for
waitress
(pip)
Oct 29, 2024
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of...
High
Unreviewed
CVE-2024-47494
was published
Oct 11, 2024
Magento Open Source Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Moderate
CVE-2024-45120
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations
Low
CVE-2024-47813
was published
for
wasmtime
(Rust)
Oct 9, 2024
Windows Kernel Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-43511
was published
Oct 8, 2024
The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to...
High
Unreviewed
CVE-2024-5803
was published
Oct 3, 2024
Duplicate Advisory: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Critical
GHSA-536j-xxhg-6pgg
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Sep 26, 2024
•
withdrawn
Duplicate Advisory: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system
Moderate
GHSA-g4pj-mx9f-m2mh
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Sep 26, 2024
•
withdrawn
This vulnerability occurs when an attacker exploits a race condition between the time a file is...
Moderate
Unreviewed
CVE-2024-6787
was published
Sep 21, 2024
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online...
High
Unreviewed
CVE-2024-27114
was published
Sep 11, 2024
In the Linux kernel, the following vulnerability has been resolved:
exec: Fix ToCToU between...
High
Unreviewed
CVE-2024-43882
was published
Aug 21, 2024
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are...
High
Unreviewed
CVE-2024-39425
was published
Aug 14, 2024
Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are...
High
Unreviewed
CVE-2024-39420
was published
Aug 14, 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38186
was published
Aug 13, 2024
Windows Kernel Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38153
was published
Aug 13, 2024
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and...
High
Unreviewed
CVE-2023-20578
was published
Aug 13, 2024
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object...
High
Unreviewed
CVE-2024-7348
was published
Aug 8, 2024
Apache StreamPipes potentially allows creation of multiple identical accounts
Moderate
CVE-2024-30471
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jul 17, 2024
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows...
Moderate
Unreviewed
CVE-2024-39821
was published
Jul 15, 2024
Path traversal in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an...
Moderate
Unreviewed
CVE-2024-39826
was published
Jul 15, 2024
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may...
High
Unreviewed
CVE-2024-27238
was published
Jul 15, 2024
A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080,...
Moderate
Unreviewed
CVE-2024-27361
was published
Jul 9, 2024
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x...
High
Unreviewed
CVE-2024-39936
was published
Jul 4, 2024
ProTip!
Advisories are also available from the
GraphQL API