GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            20 advisories
        Filter by severity
        
      
      
    
                    
                      OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
                    
                      
  High
                    
                
                      
                        CVE-2025-28382
                      
                      was published
                        for
                        
                          openc3-cosmos-tool-iframe
                        
                        (RubyGems)
                      Jun 13, 2025 
                    
                  
                    
                      actionpack Path Traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2014-0130
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Path Traversal in Action View
                    
                      
  High
                    
                
                      
                        CVE-2019-5418
                      
                      was published
                        for
                        
                          actionview
                        
                        (RubyGems)
                      Mar 13, 2019 
                    
                  
                    
                      Directory traversal vulnerability in Action View in Ruby on Rails
                    
                      
  High
                    
                
                      
                        CVE-2016-0752
                      
                      was published
                        for
                        
                          actionpack
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)
                    
                      
  High
                    
                
                      
                        GHSA-7x4w-cj9r-h4v9
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 18, 2024 
                    
                  
                    
                      Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)
                    
                      
  High
                    
                
                      
                        CVE-2024-46987
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 18, 2024 
                    
                  
                    
                      Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)
                    
                      
  High
                    
                
                      
                        CVE-2024-46986
                      
                      was published
                        for
                        
                          camaleon_cms
                        
                        (RubyGems)
                      Sep 18, 2024 
                    
                  
                    
                      OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
                    
                      
  High
                    
                
                      
                        CVE-2024-46977
                      
                      was published
                        for
                        
                          openc3
                        
                        (RubyGems)
                      Oct 2, 2024 
                    
                  
                    
                      Path Traversal vulnerability that affects yard
                    
                      
  High
                    
                
                      
                        CVE-2019-1020001
                      
                      was published
                        for
                        
                          yard
                        
                        (RubyGems)
                      Jul 2, 2019 
                    
                  
                    
                      rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
                    
                      
  High
                    
                
                      
                        CVE-2023-38337
                      
                      was published
                        for
                        
                          rswag
                        
                        (RubyGems)
                      Jul 15, 2023 
                    
                  
                    
                      Sprockets path traversal leads to information leak
                    
                      
  High
                    
                
                      
                        CVE-2018-3760
                      
                      was published
                        for
                        
                          sprockets
                        
                        (RubyGems)
                      Jun 20, 2018 
                    
                  
                    
                      archive-tar-minitar and minitar vulnerable to Path Traversal
                    
                      
  High
                    
                
                      
                        CVE-2016-10173
                      
                      was published
                        for
                        
                          archive-tar-minitar
                        
                        (RubyGems)
                      Oct 24, 2017 
                    
                  
                    
                      RubyGems Delete directory using symlink when decompressing tar
                    
                      
  High
                    
                
                      
                        CVE-2019-8320
                      
                      was published
                        for
                        
                          rubygems-update
                        
                        (RubyGems)
                      Jun 20, 2019 
                    
                  
                    
                      Directory traversal in Rack::Directory app bundled with Rack
                    
                      
  High
                    
                
                      
                        CVE-2020-8161
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Jul 6, 2020 
                    
                  
                    
                      Arbitrary file read vulnerability in yard server
                    
                      
  High
                    
                
                      
                        CVE-2017-17042
                      
                      was published
                        for
                        
                          yard
                        
                        (RubyGems)
                      Dec 21, 2017 
                    
                  
                    
                      sinatra does not validate expanded path matches
                    
                      
  High
                    
                
                      
                        CVE-2022-29970
                      
                      was published
                        for
                        
                          sinatra
                        
                        (RubyGems)
                      May 3, 2022 
                    
                  
                    
                      RubyGems may allow a maliciously crafted gem to overwrite files
                    
                      
  High
                    
                
                      
                        CVE-2017-0901
                      
                      was published
                        for
                        
                          rubygems-update
                        
                        (RubyGems)
                      May 13, 2022 
                    
                  
                    
                      mixlib-archive Path Traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2017-1000026
                      
                      was published
                        for
                        
                          mixlib-archive
                        
                        (RubyGems)
                      May 13, 2022 
                    
                  
                    
                      TZInfo relative path traversal vulnerability allows loading of arbitrary files
                    
                      
  High
                    
                
                      
                        CVE-2022-31163
                      
                      was published
                        for
                        
                          tzinfo
                        
                        (RubyGems)
                      Jul 21, 2022 
                    
                  
                    
                      Tempfile on Windows path traversal vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2021-28966
                      
                      was published
                        for
                        
                          tmpdir
                        
                        (RubyGems)
                      May 6, 2021 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API