GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,328
NuGet
761
pip
4,100
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
112 advisories
Filter by severity
OpenStack's Mistral Client has a local file inclusion vulnerability
Moderate
CVE-2021-4472
was published
for
python-mistralclient
(pip)
Nov 26, 2025
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-13380
was published
Nov 25, 2025
The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and...
Moderate
Unreviewed
CVE-2025-11973
was published
Nov 21, 2025
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow...
Moderate
Unreviewed
CVE-2025-64738
was published
Nov 13, 2025
External control of file name or path in certain Zoom Clients may allow an unauthenticated user...
Moderate
Unreviewed
CVE-2025-64739
was published
Nov 13, 2025
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control...
Moderate
Unreviewed
CVE-2022-4983
was published
Nov 13, 2025
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0...
Moderate
Unreviewed
CVE-2025-20614
was published
Nov 11, 2025
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-12137
was published
Nov 1, 2025
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.
...
Moderate
Unreviewed
CVE-2025-8050
was published
Oct 21, 2025
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal....
Moderate
Unreviewed
CVE-2025-8048
was published
Oct 20, 2025
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all...
Moderate
Unreviewed
CVE-2025-11738
was published
Oct 18, 2025
External control of file name or path in Windows Core Shell allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-59244
was published
Oct 14, 2025
External control of file name or path in Windows Core Shell allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-59185
was published
Oct 14, 2025
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts...
Moderate
Unreviewed
CVE-2025-9920
was published
Sep 9, 2025
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element...
Moderate
Unreviewed
CVE-2025-9529
was published
Aug 27, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20269
was published
Aug 20, 2025
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-53769
was published
Aug 12, 2025
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3...
Moderate
Unreviewed
CVE-2025-36506
was published
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
OctoPrint vulnerable to possible file extraction via upload endpoints
Moderate
CVE-2025-48067
was published
for
OctoPrint
(pip)
Jun 10, 2025
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-47956
was published
Jun 10, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
Kea configuration and API directives can be used to overwrite arbitrary files, subject to...
Moderate
Unreviewed
CVE-2025-32802
was published
May 28, 2025
ProTip!
Advisories are also available from the
GraphQL API