GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,933
Erlang
39
GitHub Actions
38
Go
2,597
Maven
5,000+
npm
4,248
NuGet
754
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
84 advisories
Filter by severity
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files...
High
Unreviewed
CVE-2024-48248
was published
Mar 4, 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6...
Critical
Unreviewed
CVE-2024-13159
was published
Jan 14, 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6...
Critical
Unreviewed
CVE-2024-13161
was published
Jan 14, 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6...
Critical
Unreviewed
CVE-2024-13160
was published
Jan 14, 2025
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when...
High
Unreviewed
CVE-2018-20250
was published
May 13, 2022
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Moderate
GHSA-vffh-c9pq-4crh
was published
for
uptime-kuma
(npm)
Oct 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
Deep Java Library path traversal issue
Critical
CVE-2025-0851
was published
for
ai.djl:api
(Maven)
Jan 29, 2025
The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-8575
was published
Sep 12, 2025
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-9518
was published
Sep 4, 2025
The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to,...
Moderate
Unreviewed
CVE-2025-9516
was published
Sep 4, 2025
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers...
High
Unreviewed
CVE-2025-9257
was published
Aug 22, 2025
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers...
High
Unreviewed
CVE-2025-9256
was published
Aug 22, 2025
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers...
High
Unreviewed
CVE-2025-9259
was published
Aug 22, 2025
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers...
High
Unreviewed
CVE-2025-9258
was published
Aug 22, 2025
An issue was discovered in Commvault before 11.36.60. A security vulnerability has been...
High
Unreviewed
CVE-2025-57790
was published
Aug 20, 2025
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability,...
High
Unreviewed
CVE-2025-8909
was published
Aug 13, 2025
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability,...
High
Unreviewed
CVE-2025-8912
was published
Aug 13, 2025
The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2025-8213
was published
Jul 31, 2025
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker ...
Moderate
Unreviewed
CVE-2025-53079
was published
Jul 29, 2025
The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-8009
was published
Jul 25, 2025
Jenkins HTML Publisher Plugin vulnerability displays controller file system information in its logs
Moderate
CVE-2025-53651
was published
for
org.jenkins-ci.plugins:htmlpublisher
(Maven)
Jul 9, 2025
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading...
Moderate
Unreviewed
CVE-2025-53392
was published
Jun 29, 2025
The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all...
High
Unreviewed
CVE-2025-6381
was published
Jun 28, 2025
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-5927
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API