GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,188 advisories
Filter by severity
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
Critical
CVE-2025-28384
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0...
Critical
Unreviewed
CVE-2025-46783
was published
Jun 13, 2025
Salt vulnerable to directory traversal attack in minion file cache creation
Moderate
CVE-2025-22238
was published
for
salt
(pip)
Jun 13, 2025
Salt allows arbitrary directory creation or file deletion
Moderate
CVE-2025-22240
was published
for
salt
(pip)
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix...
Moderate
Unreviewed
CVE-2025-40592
was published
Jun 12, 2025
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on...
High
Unreviewed
CVE-2025-4613
was published
Jun 12, 2025
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-47176
was published
Jun 10, 2025
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose...
High
Unreviewed
CVE-2025-37100
was published
Jun 10, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-5740
was published
Jun 10, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2025-5741
was published
Jun 10, 2025
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient...
High
Unreviewed
CVE-2025-42977
was published
Jun 10, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48267
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48130
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-47511
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48124
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-39473
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31635
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31050
was published
Jun 9, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-5880
was published
Jun 9, 2025
ProTip!
Advisories are also available from the
GraphQL API