GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
6,360 advisories
Filter by severity
Remote Command Execution in file editing in gogs
High
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Path traversal vulnerability in functional web frameworks
High
CVE-2024-38816
was published
for
org.springframework:spring-webflux
(Maven)
Sep 13, 2024
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
High
CVE-2024-56509
was published
for
changedetection.io
(pip)
Dec 27, 2024
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18....
Moderate
Unreviewed
CVE-2024-54452
was published
Dec 27, 2024
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability...
High
Unreviewed
CVE-2024-11944
was published
Dec 30, 2024
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18,...
High
Unreviewed
CVE-2024-54453
was published
Dec 27, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-56248
was published
Jan 2, 2025
path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability
Critical
CVE-2024-56198
was published
for
path-sanitizer
(npm)
Jan 2, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability
High
CVE-2024-45816
was published
for
@backstage/plugin-techdocs-backend
(npm)
Sep 17, 2024
Karmada Tar Slips in CRDs archive extraction
Moderate
CVE-2024-56514
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker...
Moderate
Unreviewed
CVE-2024-41765
was published
Jan 4, 2025
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Critical
CVE-2023-49569
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 10, 2024
YetiForceCRM Directory Traversal vulnerability
Moderate
CVE-2023-49508
was published
for
yetiforce/yetiforce-crm
(Composer)
Feb 16, 2024
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules...
High
Unreviewed
CVE-2023-30198
was published
Jun 12, 2023
The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all...
High
Unreviewed
CVE-2024-12849
was published
Jan 7, 2025
The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all...
High
Unreviewed
CVE-2024-12152
was published
Jan 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Low
Unreviewed
CVE-2024-12425
was published
Jan 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-56286
was published
Jan 7, 2025
An attacker who successfully exploited these vulnerabilities could grant read access to files. A...
Moderate
Unreviewed
CVE-2024-12429
was published
Jan 7, 2025
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative...
Moderate
Unreviewed
CVE-2024-55550
was published
Dec 10, 2024
Path traversal vulnerability in the Medialibrary module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-52953
was published
Jan 8, 2025
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2024-10585
was published
Jan 8, 2025
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up...
High
Unreviewed
CVE-2024-9939
was published
Jan 8, 2025
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially...
Moderate
Unreviewed
CVE-2024-12105
was published
Dec 31, 2024
ProTip!
Advisories are also available from the
GraphQL API