GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
449 advisories
Filter by severity
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Moderate
CVE-2025-64765
was published
for
astro
(npm)
Nov 19, 2025
lsFusion Server is vulnerable to Path Traversal through its unpackFile function
Moderate
CVE-2025-13265
was published
for
lsfusion.platform:server
(Maven)
Nov 17, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
vlife-base has Path Traversal vulnerability
Moderate
CVE-2025-13266
was published
for
io.github.wwwlike:vlife-base
(Maven)
Nov 17, 2025
lsFusion Platform has a Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
Kgateway transformation policy template can emit files from the container
Moderate
GHSA-5pmx-7r6r-wfqq
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
Liferay Portal ComboServlet denial of service via large file combination
Moderate
CVE-2025-62254
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 24, 2025
vite allows server.fs.deny bypass via backslash on Windows
Moderate
CVE-2025-62522
was published
for
vite
(npm)
Oct 20, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
Moderate
CVE-2025-61923
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
Smidge is vulnerable to Path Traversal
Moderate
CVE-2025-11842
was published
for
Smidge
(NuGet)
Oct 16, 2025
clearml is vulnerable to Path Traversal through its `safe_extract` function
Moderate
CVE-2025-8917
was published
for
clearml
(pip)
Oct 5, 2025
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
Moderate
CVE-2025-8406
was published
for
zenml
(pip)
Oct 5, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
ml-logger has path traversal in the file argument
Moderate
CVE-2025-10951
was published
for
ml-logger
(pip)
Sep 25, 2025
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Moderate
CVE-2025-58162
was published
for
mobsf
(pip)
Sep 2, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API