GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            88 advisories
        Filter by severity
        
      
      
    
                    
                      Directory traversal outside of SENDFILE_ROOT in django-sendfile2
                    
                      
  Moderate
                    
                
                      
                        GHSA-6r3c-8xf3-ggrr
                      
                      was published
                        for
                        
                          django-sendfile2
                        
                        (pip)
                      Jun 24, 2020 
                    
                  
                    
                      Django Directory Traversal via archive.extract
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-3281
                      
                      was published
                        for
                        
                          django
                        
                        (pip)
                      Mar 18, 2021 
                    
                  
                    
                      S3Scanner allows Directory Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32061
                      
                      was published
                        for
                        
                          s3scanner
                        
                        (pip)
                      Nov 30, 2021 
                    
                  
                    
                      Path Traversal in nemo-toolkit
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-22821
                      
                      was published
                        for
                        
                          nemo-toolkit
                        
                        (pip)
                      Jan 11, 2022 
                    
                  
                    
                      Path traversal in Onionshare
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-21693
                      
                      was published
                        for
                        
                          onionshare-cli
                        
                        (pip)
                      Jan 21, 2022 
                    
                  
                    
                      Mercurial Path Traversal/Link Following vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-3902
                      
                      was published
                        for
                        
                          mercurial
                        
                        (pip)
                      Feb 15, 2022 
                    
                  
                    
                      Path traversal in FreeTAKServer-UI
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-25511
                      
                      was published
                        for
                        
                          FreeTAKServer-UI
                        
                        (pip)
                      Mar 12, 2022 
                    
                  
                    
                      pgAdmin 4 Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0959
                      
                      was published
                        for
                        
                          pgadmin4
                        
                        (pip)
                      Mar 17, 2022 
                    
                  
                    
                      Roundup Directory traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2004-1444
                      
                      was published
                        for
                        
                          Roundup
                        
                        (pip)
                      Apr 29, 2022 
                    
                  
                    
                      Directory Traversal in pyftpdlib
                    
                      
  Moderate
                    
                
                      
                        CVE-2007-6736
                      
                      was published
                        for
                        
                          pyftpdlib
                        
                        (pip)
                      May 1, 2022 
                    
                  
                    
                      MoinMoin Directory traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2008-0782
                      
                      was published
                        for
                        
                          moin
                        
                        (pip)
                      May 1, 2022 
                    
                  
                    
                      Mercurial Directory traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2008-2942
                      
                      was published
                        for
                        
                          mercurial
                        
                        (pip)
                      May 1, 2022 
                    
                  
                    
                      Path Traversal in scout-browser
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-1554
                      
                      was published
                        for
                        
                          scout-browser
                        
                        (pip)
                      May 4, 2022 
                    
                  
                    
                      SaltStack Salt Directory Traversal vulnerability in salt-api
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-15750
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      May 13, 2022 
                    
                  
                    
                      Withdrawn Advisory: Pulp Improper Path Parsing
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-10917
                      
                      was published
                        for
                        
                          pulpcore
                        
                        (pip)
                      May 13, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-1195
                      
                      was published
                        for
                        
                          glance
                        
                        (pip)
                      May 14, 2022 
                    
                  
                    
                      OpenStack Nova Multiple directory traversal vulnerabilities
                    
                      
  Moderate
                    
                
                      
                        CVE-2011-4596
                      
                      was published
                        for
                        
                          nova
                        
                        (pip)
                      May 14, 2022 
                    
                  
                    
                      Plone vulnerable to filesystem information leak
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-7135
                      
                      was published
                        for
                        
                          Plone
                        
                        (pip)
                      May 14, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API