GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,685
Maven
5,000+
npm
4,318
NuGet
760
pip
4,092
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,403 advisories
Filter by severity
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
High
CVE-2025-66295
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Gin-vue-admin has an arbitrary file deletion vulnerability
High
CVE-2025-66410
was published
for
github.com/flipped-aurora/gin-vue-admin
(Go)
Dec 2, 2025
Keras Directory Traversal Vulnerability
High
CVE-2025-12060
was published
for
keras
(pip)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
GHSA-28jp-44vh-q42h
was published
for
keras
(pip)
Oct 30, 2025
•
withdrawn
Grav vulnerable to Path Traversal allowing server files backup
Moderate
CVE-2025-66302
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Arbitrary File Read
High
CVE-2025-66300
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12638
was published
for
Keras
(pip)
Nov 28, 2025
•
withdrawn
SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides...
High
Unreviewed
CVE-2025-63365
was published
Dec 1, 2025
IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse...
Moderate
Unreviewed
CVE-2025-36114
was published
Aug 20, 2025
A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted...
Moderate
Unreviewed
CVE-2025-13816
was published
Dec 1, 2025
A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of...
Moderate
Unreviewed
CVE-2025-13810
was published
Dec 1, 2025
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common...
Moderate
Unreviewed
CVE-2025-13791
was published
Nov 30, 2025
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names....
Moderate
Unreviewed
CVE-2025-12972
was published
Nov 24, 2025
Improper input sanitization in the file archives upload functionality of Eaton Galileo software...
High
Unreviewed
CVE-2025-59890
was published
Nov 27, 2025
Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Execution
High
CVE-2025-54386
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 1, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
esm.sh CDN service has arbitrary file write via tarslip
High
CVE-2025-65025
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Moderate
CVE-2025-64765
was published
for
astro
(npm)
Nov 19, 2025
Traefik allows path traversal using url encoding
Low
CVE-2025-47952
was published
for
github.com/traefik/traefik
(Go)
May 28, 2025
Traefik has a possible vulnerability with its path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
lsFusion Server is vulnerable to Path Traversal through its unpackFile function
Moderate
CVE-2025-13265
was published
for
lsfusion.platform:server
(Maven)
Nov 17, 2025
Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S...
High
Unreviewed
CVE-2025-66251
was published
Nov 26, 2025
ProTip!
Advisories are also available from the
GraphQL API