GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,176 advisories
Filter by severity
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-49415
was published
Jun 17, 2025
A path traversal vulnerability exists in the file dropoff functionality
of ZendTo versions 6.15...
Moderate
Unreviewed
CVE-2025-34508
was published
Jun 17, 2025
python-a2a has a path traversal in the create_workflow function
Moderate
CVE-2025-6167
was published
for
python-a2a
(pip)
Jun 17, 2025
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This...
Moderate
Unreviewed
CVE-2025-6166
was published
Jun 17, 2025
A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This...
Moderate
Unreviewed
CVE-2025-6152
was published
Jun 17, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic....
Moderate
Unreviewed
CVE-2025-6109
was published
Jun 16, 2025
A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to...
Moderate
Unreviewed
CVE-2025-6108
was published
Jun 16, 2025
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows...
High
Unreviewed
CVE-2025-5964
was published
Jun 15, 2025
The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all...
Moderate
Unreviewed
CVE-2025-6070
was published
Jun 14, 2025
The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to...
Critical
Unreviewed
CVE-2025-6065
was published
Jun 14, 2025
The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-4187
was published
Jun 14, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
Critical
CVE-2025-28384
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0...
Critical
Unreviewed
CVE-2025-46783
was published
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to directory traversal attack in minion file cache creation
Moderate
CVE-2025-22238
was published
for
salt
(pip)
Jun 13, 2025
Salt allows arbitrary directory creation or file deletion
Moderate
CVE-2025-22240
was published
for
salt
(pip)
Jun 13, 2025
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix...
Moderate
Unreviewed
CVE-2025-40592
was published
Jun 12, 2025
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on...
High
Unreviewed
CVE-2025-4613
was published
Jun 12, 2025
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-47176
was published
Jun 10, 2025
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API