GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,580
Maven
5,000+
npm
5,000+
NuGet
919
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645
Moderate
GHSA-5qvp-pr9f-2g2v
was published
for
poetry-plugin-tweak-dependencies-version
(pip)
Apr 1, 2026
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
Moderate
CVE-2026-25645
was published
for
requests
(pip)
Mar 25, 2026
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in...
Moderate
Unreviewed
CVE-2026-20651
was published
Mar 25, 2026
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-20618
was published
Feb 12, 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Standard
Installer (SFX)
on...
Moderate
Unreviewed
CVE-2025-14614
was published
Jan 7, 2026
Insecure Temporary File vulnerability in Altera Quartus Prime Pro
Installer (SFX)
on Windows...
Moderate
Unreviewed
CVE-2025-14612
was published
Jan 7, 2026
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
Moderate
CVE-2025-66625
was published
for
Umbraco.Cms
(NuGet)
Dec 9, 2025
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure...
Moderate
Unreviewed
CVE-2025-46368
was published
Nov 13, 2025
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has...
Moderate
Unreviewed
CVE-2025-61659
was published
Sep 29, 2025
Insecure Temporary File usage in github.com/golang/glog
Moderate
CVE-2024-45339
was published
for
github.com/golang/glog
(Go)
Jan 28, 2025
Products for macOS enables a user logged on to the system to perform a denial-of-service attack,...
Moderate
Unreviewed
CVE-2024-6654
was published
Sep 27, 2024
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an...
Moderate
Unreviewed
CVE-2024-5742
was published
Jun 12, 2024
In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names...
Moderate
Unreviewed
CVE-2024-34490
was published
May 5, 2024
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in...
Moderate
Unreviewed
CVE-2024-23287
was published
Mar 8, 2024
Active Support Possibly Discloses Locally Encrypted Files
Moderate
CVE-2023-38037
was published
for
activesupport
(RubyGems)
Aug 23, 2023
transformers has Insecure Temporary File
Moderate
CVE-2023-2800
was published
for
transformers
(pip)
May 18, 2023
Java Merge-sort Insecure Temporary File vulnerability
Moderate
CVE-2022-24913
was published
for
com.fasterxml.util:java-merge-sort
(Maven)
Jan 12, 2023
Previously Firefox for macOS and Linux would download temporary files to a user-specific...
Moderate
Unreviewed
CVE-2022-26386
was published
Dec 22, 2022
A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is...
Moderate
Unreviewed
CVE-2022-4641
was published
Dec 22, 2022
A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this...
Moderate
Unreviewed
CVE-2022-3969
was published
Nov 13, 2022
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a...
Moderate
Unreviewed
CVE-2017-20147
was published
Sep 21, 2022
ansible-runner vulnerable to Race Condition
Moderate
CVE-2021-3702
was published
for
ansible-runner
(pip)
Aug 24, 2022
A Insecure Temporary File vulnerability in openldap2 of SUSE Linux Enterprise Server 15-LTSS,...
Moderate
Unreviewed
CVE-2020-8027
was published
May 24, 2022
A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers...
Moderate
Unreviewed
CVE-2020-8030
was published
May 24, 2022
Insecure Temporary File in Jinja2
Moderate
CVE-2014-0012
was published
for
Jinja2
(pip)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API