Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

39 advisories

Loading
poetry-plugin-tweak-dependencies-version affected by CVE-2026-25645 Moderate
GHSA-5qvp-pr9f-2g2v was published for poetry-plugin-tweak-dependencies-version (pip) Apr 1, 2026
Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function Moderate
CVE-2026-25645 was published for requests (pip) Mar 25, 2026
Jaycelation Credited to Jaycelation, nateprewitt, and sigmavirus24 nateprewitt nateprewitt
sigmavirus24 sigmavirus24
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality Moderate
CVE-2025-66625 was published for Umbraco.Cms (NuGet) Dec 9, 2025
Insecure Temporary File usage in github.com/golang/glog Moderate
CVE-2024-45339 was published for github.com/golang/glog (Go) Jan 28, 2025
Active Support Possibly Discloses Locally Encrypted Files Moderate
CVE-2023-38037 was published for activesupport (RubyGems) Aug 23, 2023
transformers has Insecure Temporary File Moderate
CVE-2023-2800 was published for transformers (pip) May 18, 2023
sfblackl-intel Credited to sfblackl-intel
Java Merge-sort Insecure Temporary File vulnerability Moderate
CVE-2022-24913 was published for com.fasterxml.util:java-merge-sort (Maven) Jan 12, 2023
Previously Firefox for macOS and Linux would download temporary files to a user-specific... Moderate Unreviewed
CVE-2022-26386 was published Dec 22, 2022
ansible-runner vulnerable to Race Condition Moderate
CVE-2021-3702 was published for ansible-runner (pip) Aug 24, 2022
Insecure Temporary File in Jinja2 Moderate
CVE-2014-0012 was published for Jinja2 (pip) May 17, 2022
ProTip! Advisories are also available from the GraphQL API