GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,236 advisories
Filter by severity
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
A path traversal vulnerability was discovered in the Time Machine functionality due to missing...
High
Unreviewed
CVE-2025-40889
was published
Oct 7, 2025
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to...
High
Unreviewed
CVE-2025-59744
was published
Oct 2, 2025
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL...
High
Unreviewed
CVE-2025-11020
was published
Oct 2, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code...
High
Unreviewed
CVE-2025-11182
was published
Oct 2, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-59002
was published
Sep 26, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-10449
was published
Sep 25, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since...
High
Unreviewed
CVE-2025-56815
was published
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the...
High
Unreviewed
CVE-2025-56816
was published
Sep 24, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-10468
was published
Sep 19, 2025
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure...
High
Unreviewed
CVE-2025-34185
was published
Sep 16, 2025
The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2025-10176
was published
Sep 13, 2025
The User Meta – User Profile Builder and User management plugin plugin for WordPress is...
High
Unreviewed
CVE-2025-9693
was published
Sep 11, 2025
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
High
Unreviewed
CVE-2025-58320
was published
Sep 11, 2025
A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server ...
High
Unreviewed
CVE-2025-9918
was published
Sep 11, 2025
xml2rfc is vulnerable to arbitrary file reads through prepped files
High
CVE-2025-11059
was published
for
xml2rfc
(pip)
Sep 10, 2025
The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path...
High
Unreviewed
CVE-2025-41714
was published
Sep 10, 2025
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to...
High
Unreviewed
CVE-2025-23343
was published
Sep 9, 2025
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
High
CVE-2025-58755
was published
for
monai
(pip)
Sep 9, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability...
High
Unreviewed
CVE-2025-41035
was published
Sep 4, 2025
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-7975
was published
Sep 2, 2025
ProTip!
Advisories are also available from the
GraphQL API