GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
830 advisories
Filter by severity
Aim path traversal in LockManager.release_locks
Critical
CVE-2024-8769
was published
for
aim
(pip)
Mar 20, 2025
AgentScope path traversal vulnerability in save-workflow
Critical
CVE-2024-8551
was published
for
agentscope
(pip)
Mar 20, 2025
AgentScope path traversal vulnerability
Critical
CVE-2024-8537
was published
for
agentscope
(pip)
Mar 20, 2025
A path traversal vulnerability exists in stitionai/devika, specifically in the project creation...
Critical
Unreviewed
CVE-2024-5752
was published
Mar 20, 2025
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to...
Critical
Unreviewed
CVE-2025-2505
was published
Mar 20, 2025
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-1661
was published
Mar 11, 2025
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may...
Critical
Unreviewed
CVE-2024-53676
was published
Nov 27, 2024
Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account
Critical
CVE-2025-27590
was published
for
oxidized-web
(RubyGems)
Mar 3, 2025
In XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible,...
Critical
Unreviewed
CVE-2024-38292
was published
Feb 28, 2025
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources....
Critical
Unreviewed
CVE-2024-51549
was published
Dec 5, 2024
Mattermost allows reading arbitrary files
Critical
CVE-2025-20051
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost allows reading arbitrary files related to importing boards
Critical
CVE-2025-25279
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
This vulnerability allows remote attackers to delete arbitrary files on affected installations of...
Critical
Unreviewed
CVE-2022-2560
was published
Mar 29, 2023
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all...
Critical
Unreviewed
CVE-2024-13725
was published
Feb 18, 2025
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged...
Critical
Unreviewed
CVE-2025-1127
was published
Feb 13, 2025
Path Traversal in Apache Shiro
Critical
CVE-2023-34478
was published
for
org.apache.shiro:shiro-web
(Maven)
Jul 24, 2023
The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
Critical
Unreviewed
CVE-2024-10763
was published
Feb 13, 2025
WhoDB has a path traversal opening Sqlite3 database
Critical
CVE-2025-24786
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress...
Critical
Unreviewed
CVE-2025-0493
was published
Jan 31, 2025
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is...
Critical
Unreviewed
CVE-2024-40422
was published
Jul 24, 2024
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions...
Critical
Unreviewed
CVE-2024-13545
was published
Jan 24, 2025
PaddlePaddle Path Traversal vulnerability
Critical
CVE-2024-0818
was published
for
paddlepaddle
(pip)
Mar 7, 2024
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File...
Critical
Unreviewed
CVE-2024-26261
was published
Feb 15, 2024
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all...
Critical
Unreviewed
CVE-2021-26102
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API