GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,183 advisories
Filter by severity
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
Moderate
CVE-2025-6773
was published
for
lightrag-hku
(pip)
Jun 27, 2025
raspap-webgui has a Directory Traversal vulnerability
High
CVE-2025-44163
was published
for
billz/raspap-webgui
(Composer)
Jun 27, 2025
A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-6925
was published
Jun 30, 2025
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote...
High
Unreviewed
CVE-2025-34058
was published
Jul 1, 2025
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
High
Unreviewed
CVE-2025-37098
was published
Jul 1, 2025
The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2025-5014
was published
Jul 2, 2025
The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-4946
was published
Jul 2, 2025
Path traversal in WebGUI HTTP endpoint in Infinera G42 version R6.1.3
allows remote...
High
Unreviewed
CVE-2025-27022
was published
Jul 2, 2025
Sending a crafted SOAP "provision" operation message archive field within the Mobile Network...
Moderate
Unreviewed
CVE-2025-24329
was published
Jul 2, 2025
Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network...
Moderate
Unreviewed
CVE-2025-24330
was published
Jul 2, 2025
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Moderate
Unreviewed
CVE-2025-37095
was published
Jun 2, 2025
@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix
High
CVE-2025-53110
was published
for
@modelcontextprotocol/server-filesystem
(npm)
Jul 1, 2025
Directory traversal vulnerability in the Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4...
High
Unreviewed
CVE-2012-6069
was published
May 17, 2022
python-a2a has a path traversal in the create_workflow function
Moderate
CVE-2025-6167
was published
for
python-a2a
(pip)
Jun 17, 2025
Microweber CMS API has authenticated local file inclusion vulnerability
Moderate
CVE-2025-34076
was published
for
microweber/microweber
(Composer)
Jul 2, 2025
The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-2932
was published
Jul 3, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-49303
was published
Jul 4, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-28980
was published
Jul 4, 2025
A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected...
Moderate
Unreviewed
CVE-2025-7107
was published
Jul 7, 2025
A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6...
Moderate
Unreviewed
CVE-2025-7108
was published
Jul 7, 2025
Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure...
Moderate
Unreviewed
CVE-2025-6795
was published
Jul 7, 2025
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and...
Critical
Unreviewed
CVE-2025-6793
was published
Jul 7, 2025
Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability...
High
Unreviewed
CVE-2025-6796
was published
Jul 7, 2025
Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This...
High
Unreviewed
CVE-2025-6806
was published
Jul 7, 2025
Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability....
High
Unreviewed
CVE-2025-6798
was published
Jul 7, 2025
ProTip!
Advisories are also available from the
GraphQL API