GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,183 advisories
Filter by severity
A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This...
Moderate
Unreviewed
CVE-2025-6152
was published
Jun 17, 2025
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This...
Moderate
Unreviewed
CVE-2025-6166
was published
Jun 17, 2025
A path traversal vulnerability exists in the file dropoff functionality
of ZendTo versions 6.15...
Moderate
Unreviewed
CVE-2025-34508
was published
Jun 17, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-49415
was published
Jun 17, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-49879
was published
Jun 17, 2025
A path handling issue was addressed with improved validation. This issue is fixed in macOS...
Low
Unreviewed
CVE-2023-40383
was published
Jan 11, 2024
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID...
High
Unreviewed
CVE-2021-46902
was published
Feb 4, 2024
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
Critical
CVE-2025-28384
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6...
Critical
Unreviewed
CVE-2024-10811
was published
Jan 14, 2025
Taylored webhook validation vulnerabilities
Critical
GHSA-8g98-m4j9-qww5
was published
for
taylored
(npm)
Jun 18, 2025
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload...
High
Unreviewed
CVE-2023-45723
was published
Jan 3, 2024
A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify...
Moderate
Unreviewed
CVE-2024-12088
was published
Jan 14, 2025
A path transversal vulnerability in
Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local...
Moderate
Unreviewed
CVE-2025-4661
was published
Jun 19, 2025
DotVVM allows path traversal when deployed in Debug mode
High
GHSA-6q65-j4jw-9cg8
was published
for
DotVVM
(NuGet)
Jun 19, 2025
A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb...
Moderate
Unreviewed
CVE-2025-6282
was published
Jun 20, 2025
A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic...
Moderate
Unreviewed
CVE-2025-6283
was published
Jun 20, 2025
A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-6281
was published
Jun 20, 2025
A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to...
Moderate
Unreviewed
CVE-2025-6280
was published
Jun 20, 2025
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter
Moderate
CVE-2006-3934
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter
Moderate
CVE-2008-1301
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras,...
Critical
Unreviewed
CVE-2025-34022
was published
Jun 20, 2025
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The ...
High
Unreviewed
CVE-2025-34023
was published
Jun 20, 2025
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice...
High
Unreviewed
CVE-2023-48166
was published
Jan 13, 2024
ProTip!
Advisories are also available from the
GraphQL API