GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,329
NuGet
762
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
65 advisories
Filter by severity
Potential URI resolution path traversal in the AWS SDK for PHP
Moderate
CVE-2023-51651
was published
for
aws/aws-sdk-php
(Composer)
Dec 21, 2023
baserCMS Directory Traversal vulnerability in Form submission data management Feature
Moderate
CVE-2023-43648
was published
for
baserproject/basercms
(Composer)
Oct 26, 2023
PrestaShop file access through path traversal
Moderate
CVE-2023-39528
was published
for
prestashop/prestashop
(Composer)
Aug 9, 2023
PrestaShop path traversal
Moderate
CVE-2023-39525
was published
for
prestashop/prestashop
(Composer)
Aug 9, 2023
Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction
Moderate
CVE-2023-38708
was published
for
pimcore/pimcore
(Composer)
Aug 3, 2023
Pimcore Path Traversal Vulnerability in AdminBundle/Controller/Reports/CustomReportController.php
Moderate
CVE-2023-30855
was published
for
pimcore/pimcore
(Composer)
May 2, 2023
Arbitrary File Read in Admin JS CSS files
Moderate
CVE-2023-30852
was published
for
pimcore/pimcore
(Composer)
Apr 27, 2023
Path Traversal in Asset "import from server" option
Moderate
CVE-2023-2336
was published
for
pimcore/pimcore
(Composer)
Apr 27, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
Moderate
CVE-2023-27577
was published
for
flarum/core
(Composer)
Mar 13, 2023
SUKOHI Surpass Path Traversal vulnerability
Moderate
CVE-2015-10030
was published
for
sukohi/surpass
(Composer)
Jan 8, 2023
UniSharp Laravel Filemanager directory traversal vulnerability
Moderate
CVE-2022-40734
was published
for
unisharp/laravel-filemanager
(Composer)
Sep 15, 2022
Path Traversal in FileGator
Moderate
CVE-2022-1850
was published
for
filegator/filegator
(Composer)
May 25, 2022
Magento Path Traversal vulnerability
Moderate
CVE-2021-28584
was published
for
magento/community-edition
(Composer)
May 24, 2022
Grav CMS Local File Injection
Moderate
CVE-2020-29556
was published
for
getgrav/grav
(Composer)
May 24, 2022
browsershot local file inclusion vulnerability
Moderate
CVE-2020-7790
was published
for
spatie/browsershot
(Composer)
May 24, 2022
Magento path traversal vulnerability
Moderate
CVE-2020-9689
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Path Traversal
Moderate
CVE-2020-3717
was published
for
magento/community-edition
(Composer)
May 24, 2022
TYPO3 Directory Traversal on ZIP extraction
Moderate
CVE-2019-19848
was published
for
typo3/cms
(Composer)
May 24, 2022
Magento Insecure Direct Object Reference (IDOR) vulnerability
Moderate
CVE-2019-7925
was published
for
magento/community-edition
(Composer)
May 24, 2022
ImpressCMS Path Traversal to Arbitrary File Delete
Moderate
CVE-2014-1836
was published
for
impresscms/impresscms
(Composer)
May 17, 2022
Contao Core directory traversal vulnerability
Moderate
CVE-2015-0269
was published
for
contao/core
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
Moderate
CVE-2011-0986
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 Directory Traversal vulnerability
Moderate
CVE-2010-5101
was published
for
typo3/cms
(Composer)
May 17, 2022
TYPO3 Path Traversal vulnerability
Moderate
CVE-2010-5099
was published
for
typo3/cms
(Composer)
May 17, 2022
phpMyAdmin Directory Traversal Vulnerability
Moderate
CVE-2011-2718
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API