GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,891
Erlang
37
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,221
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,256 advisories
Filter by severity
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-11631
was published
Oct 12, 2025
A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function...
Moderate
Unreviewed
CVE-2025-11630
was published
Oct 12, 2025
A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element...
Moderate
Unreviewed
CVE-2025-11607
was published
Oct 11, 2025
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in...
Moderate
Unreviewed
CVE-2025-9950
was published
Oct 11, 2025
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design...
Critical
Unreviewed
CVE-2025-6439
was published
Oct 11, 2025
cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
High
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager...
High
Unreviewed
CVE-2023-41973
was published
Mar 26, 2024
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated...
High
Unreviewed
CVE-2025-35055
was published
Oct 9, 2025
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability...
High
Unreviewed
CVE-2025-34248
was published
Oct 9, 2025
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying...
Moderate
Unreviewed
CVE-2025-35053
was published
Oct 9, 2025
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an...
Moderate
Unreviewed
CVE-2025-35056
was published
Oct 9, 2025
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows...
High
Unreviewed
CVE-2025-5964
was published
Jun 15, 2025
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and...
High
Unreviewed
CVE-2025-39664
was published
Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is...
Critical
Unreviewed
CVE-2025-7526
was published
Oct 9, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-47211
was published
Oct 3, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43889
was published
Oct 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
Moderate
Unreviewed
CVE-2025-43934
was published
Oct 7, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
Moderate
Unreviewed
CVE-2025-33034
was published
Oct 3, 2025
A client-side path traversal vulnerability was discovered in the web management interface front...
Moderate
Unreviewed
CVE-2025-3718
was published
Oct 7, 2025
ProTip!
Advisories are also available from the
GraphQL API