GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
709 advisories
Filter by severity
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Low
GHSA-f2wx-xjfw-xjv6
was published
for
topgrade
(Rust)
Jul 17, 2023
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2023-23520
was published
Feb 27, 2023
A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests....
Low
Unreviewed
CVE-2023-5760
was published
Nov 8, 2023
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU)...
High
Unreviewed
CVE-2023-38041
was published
Oct 25, 2023
FoodCoopShop Server-Side Request Forgery vulnerability
High
CVE-2023-46725
was published
for
foodcoopshop/foodcoopshop
(Composer)
Nov 2, 2023
A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage...
Moderate
Unreviewed
CVE-2022-3700
was published
Oct 27, 2023
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin...
High
Unreviewed
CVE-2022-3701
was published
Oct 27, 2023
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3...
High
Unreviewed
CVE-2022-3702
was published
Oct 27, 2023
A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in...
High
Unreviewed
CVE-2023-1295
was published
Jun 28, 2023
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a...
Moderate
Unreviewed
CVE-2023-6803
was published
Dec 21, 2023
A race condition in GitHub Enterprise Server was identified that could allow an attacker...
Moderate
Unreviewed
CVE-2023-46649
was published
Dec 21, 2023
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on...
Low
Unreviewed
CVE-2023-6690
was published
Dec 21, 2023
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos...
Moderate
Unreviewed
CVE-2023-42483
was published
Dec 13, 2023
TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29,...
Moderate
Unreviewed
CVE-2022-24351
was published
Dec 16, 2023
Buildkite Elastic CI for AWS time-of-check-time-of-use race condition vulnerability
High
CVE-2023-43741
was published
for
github.com/buildkite/elastic-ci-stack-for-aws/v6
(Go)
Dec 22, 2023
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly...
High
Unreviewed
CVE-2020-1337
was published
May 24, 2022
External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use...
Low
Unreviewed
CVE-2023-26438
was published
Aug 2, 2023
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of...
High
Unreviewed
CVE-2023-2007
was published
Apr 25, 2023
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated,...
High
Unreviewed
CVE-2023-20135
was published
Sep 13, 2023
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Critical
CVE-2021-32708
was published
for
league/flysystem
(Composer)
Jun 29, 2021
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in telemetry processing of...
Moderate
Unreviewed
CVE-2023-44188
was published
Oct 11, 2023
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM...
Moderate
Unreviewed
CVE-2023-20521
was published
Nov 14, 2023
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation...
High
Unreviewed
CVE-2022-47631
was published
Sep 15, 2023
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition...
Moderate
Unreviewed
CVE-2024-0163
was published
Mar 13, 2024
ProTip!
Advisories are also available from the
GraphQL API