GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,303
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
669
pip
3,430
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,710 advisories
Filter by severity
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An...
Moderate
Unreviewed
CVE-2024-12083
was published
Jan 14, 2025
A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the...
Moderate
Unreviewed
CVE-2025-0401
was published
Jan 13, 2025
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system...
Moderate
Unreviewed
CVE-2023-25750
was published
Jun 2, 2023
When downloading files through the Save As dialog on Windows with suggested filenames containing...
Moderate
Unreviewed
CVE-2023-28163
was published
Jun 2, 2023
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
keras Path Traversal vulnerability
Moderate
CVE-2024-55459
was published
for
keras
(pip)
Jan 8, 2025
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially...
Moderate
Unreviewed
CVE-2024-12105
was published
Dec 31, 2024
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2024-10585
was published
Jan 8, 2025
Path traversal vulnerability in the Medialibrary module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-52953
was published
Jan 8, 2025
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative...
Moderate
Unreviewed
CVE-2024-55550
was published
Dec 10, 2024
An attacker who successfully exploited these vulnerabilities could grant read access to files. A...
Moderate
Unreviewed
CVE-2024-12429
was published
Jan 7, 2025
YetiForceCRM Directory Traversal vulnerability
Moderate
CVE-2023-49508
was published
for
yetiforce/yetiforce-crm
(Composer)
Feb 16, 2024
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker...
Moderate
Unreviewed
CVE-2024-41765
was published
Jan 4, 2025
Karmada Tar Slips in CRDs archive extraction
Moderate
CVE-2024-56514
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-56248
was published
Jan 2, 2025
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18....
Moderate
Unreviewed
CVE-2024-54452
was published
Dec 27, 2024
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12850
was published
Dec 24, 2024
uptime-kuma vulnerable to Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitor
Moderate
CVE-2024-56331
was published
for
uptime-kuma
(npm)
Dec 20, 2024
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3....
Moderate
Unreviewed
CVE-2024-12793
was published
Dec 19, 2024
PGHoard Path Traversal vulnerability
Moderate
CVE-2024-56142
was published
for
pghoard
(pip)
Dec 17, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-54382
was published
Dec 16, 2024
A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-12362
was published
Dec 16, 2024
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic....
Moderate
Unreviewed
CVE-2024-12482
was published
Dec 12, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-54259
was published
Dec 13, 2024
Buildah allows arbitrary directory mount
Moderate
CVE-2024-9675
was published
for
github.com/containers/buildah
(Go)
Oct 9, 2024
ProTip!
Advisories are also available from the
GraphQL API