GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,227 advisories
Filter by severity
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54029
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-54819
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-58072
was published
Aug 28, 2025
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON...
High
Unreviewed
CVE-2024-13982
was published
Aug 28, 2025
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to...
High
Unreviewed
CVE-2025-50971
was published
Aug 26, 2025
xml2rfc has an arbitrary file read vulnerability
High
CVE-2025-11058
was published
for
xml2rfc
(pip)
Aug 26, 2025
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
High
Unreviewed
CVE-2025-29420
was published
Aug 26, 2025
In MindManager Windows versions prior to 24.1.150, attackers could potentially write to...
High
Unreviewed
CVE-2024-56179
was published
Aug 22, 2025
Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall...
High
Unreviewed
CVE-2010-20109
was published
Aug 21, 2025
Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows...
High
Unreviewed
CVE-2012-10061
was published
Aug 20, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-54926
was published
Aug 20, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54021
was published
Aug 20, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48158
was published
Aug 20, 2025
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion...
High
Unreviewed
CVE-2025-8141
was published
Aug 20, 2025
Copier's safe template has arbitrary filesystem read/write access
High
CVE-2025-55201
was published
for
copier
(pip)
Aug 18, 2025
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File...
High
Unreviewed
CVE-2025-3671
was published
Aug 16, 2025
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory...
High
Unreviewed
CVE-2025-7641
was published
Aug 15, 2025
Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py
High
CVE-2025-50817
was published
for
future
(pip)
Aug 14, 2025
•
withdrawn
S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p...
High
Unreviewed
CVE-2011-10009
was published
Aug 13, 2025
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component,...
High
Unreviewed
CVE-2025-23304
was published
Aug 13, 2025
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled...
High
Unreviewed
CVE-2025-8941
was published
Aug 13, 2025
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability,...
High
Unreviewed
CVE-2025-8912
was published
Aug 13, 2025
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability,...
High
Unreviewed
CVE-2025-8909
was published
Aug 13, 2025
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information...
High
Unreviewed
CVE-2025-53793
was published
Aug 12, 2025
The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due...
High
Unreviewed
CVE-2025-5391
was published
Aug 12, 2025
ProTip!
Advisories are also available from the
GraphQL API