GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
126 advisories
Filter by severity
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in...
Low
Unreviewed
CVE-2024-20805
was published
Jan 4, 2024
Winter CMS Local File Inclusion through Server Side Template Injection
Low
CVE-2023-52085
was published
for
winter/wn-backend-module
(Composer)
Jan 2, 2024
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Low
CVE-2023-49089
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient...
Low
Unreviewed
CVE-2023-49058
was published
Dec 12, 2023
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified...
Low
Unreviewed
CVE-2018-25094
was published
Dec 3, 2023
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to...
Low
Unreviewed
CVE-2023-6160
was published
Nov 22, 2023
It was discovered that Kibana was not validating a user supplied path, which would load .pbf...
Low
Unreviewed
CVE-2021-22151
was published
Nov 22, 2023
sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)
Low
CVE-2023-46122
was published
for
org.scala-sbt:io_2.12
(Maven)
Oct 24, 2023
Pleroma Path Traversal vulnerability
Low
CVE-2023-5588
was published
for
pleroma
(Erlang)
Oct 16, 2023
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic....
Low
Unreviewed
CVE-2023-5327
was published
Oct 2, 2023
A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as...
Low
Unreviewed
CVE-2023-5257
was published
Sep 29, 2023
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR...
Low
Unreviewed
CVE-2023-5142
was published
Sep 25, 2023
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
Low
CVE-2023-41057
was published
for
hyper-bump-it
(pip)
Sep 4, 2023
The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url...
Low
Unreviewed
CVE-2023-4216
was published
Sep 4, 2023
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized...
Low
Unreviewed
CVE-2023-34117
was published
Jul 11, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a...
Low
Unreviewed
CVE-2023-25186
was published
Jun 16, 2023
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this...
Low
Unreviewed
CVE-2023-3241
was published
Jun 14, 2023
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3,...
Low
Unreviewed
CVE-2022-42474
was published
Jun 13, 2023
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter...
Low
Unreviewed
CVE-2023-2117
was published
May 30, 2023
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1...
Low
Unreviewed
CVE-2023-29128
was published
May 9, 2023
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal...
Low
Unreviewed
CVE-2023-27409
was published
May 9, 2023
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access...
Low
Unreviewed
CVE-2023-21448
was published
Feb 9, 2023
The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input...
Low
Unreviewed
CVE-2022-4109
was published
Jan 3, 2023
ProTip!
Advisories are also available from the
GraphQL API