GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,184 advisories
Filter by severity
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4138
was published
Jun 3, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4330
was published
Jun 3, 2025
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter...
Critical
Unreviewed
CVE-2025-4517
was published
Jun 3, 2025
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to...
Moderate
Unreviewed
CVE-2025-5545
was published
Jun 4, 2025
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5....
Moderate
Unreviewed
CVE-2025-5544
was published
Jun 4, 2025
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an...
Low
Unreviewed
CVE-2025-20277
was published
Jun 4, 2025
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows...
Moderate
Unreviewed
CVE-2025-20259
was published
Jun 4, 2025
Improper handling of input variables lead to multiple path traversal vulnerabilities in the...
High
Unreviewed
CVE-2025-22205
was published
Feb 4, 2025
Arbitrary file read vulnerability in Git server Plugin can lead to RCE
High
CVE-2024-23899
was published
for
org.jenkins-ci.plugins:git-server
(Maven)
Jan 24, 2024
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-3055
was published
Jun 5, 2025
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as...
Moderate
Unreviewed
CVE-2025-5714
was published
Jun 6, 2025
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker...
High
Unreviewed
CVE-2025-33035
was published
Jun 6, 2025
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-3485
was published
Jun 6, 2025
A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-5880
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31050
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-39473
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31635
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-47511
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48267
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48130
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48124
was published
Jun 9, 2025
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient...
High
Unreviewed
CVE-2025-42977
was published
Jun 10, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2025-5741
was published
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API