GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,688
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
99 advisories
Filter by severity
H2O Vulnerable to Arbitrary File Overwrite
High
CVE-2024-8616
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems...
High
Unreviewed
CVE-2025-0452
was published
Mar 20, 2025
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3...
High
Unreviewed
CVE-2023-45588
was published
Mar 14, 2025
Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under...
High
Unreviewed
CVE-2024-41183
was published
Oct 22, 2024
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to,...
High
Unreviewed
CVE-2024-12036
was published
Mar 7, 2025
There is a local file inclusion vulnerability in ArcGIS Server 10.9.1 thru 11.3 that may allow a...
High
Unreviewed
CVE-2024-51961
was published
Mar 3, 2025
Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro
High
CVE-2025-1686
was published
for
io.pebbletemplates:pebble
(Maven)
Feb 28, 2025
HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the...
High
Unreviewed
CVE-2025-25761
was published
Feb 27, 2025
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27944
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import...
High
Unreviewed
CVE-2024-27945
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27943
was published
May 14, 2024
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
High
CVE-2024-1603
was published
for
paddlepaddle
(pip)
Mar 23, 2024
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2024-12066
was published
Dec 21, 2024
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows...
High
Unreviewed
CVE-2024-4230
was published
Dec 19, 2024
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
High
CVE-2019-14905
was published
for
ansible
(pip)
Apr 20, 2021
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43581
was published
Oct 8, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43615
was published
Oct 8, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-38029
was published
Oct 8, 2024
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2. 11.1, 11.0 and 10.9...
High
Unreviewed
CVE-2024-38040
was published
Oct 4, 2024
Proxmox Virtual Environment is an open-source server management platform for enterprise...
High
Unreviewed
CVE-2024-21545
was published
Sep 25, 2024
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A...
High
Unreviewed
CVE-2023-28603
was published
Jun 13, 2023
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for...
High
Unreviewed
CVE-2024-7626
was published
Sep 11, 2024
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec...
High
Unreviewed
CVE-2024-33671
was published
Apr 26, 2024
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows...
High
Unreviewed
CVE-2024-6255
was published
Jul 31, 2024
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local...
High
Unreviewed
CVE-2024-6714
was published
Jul 23, 2024
ProTip!
Advisories are also available from the
GraphQL API