GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,176 advisories
Filter by severity
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON...
High
Unreviewed
CVE-2024-13982
was published
Aug 28, 2025
A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an...
Moderate
Unreviewed
CVE-2025-20344
was published
Aug 27, 2025
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to...
High
Unreviewed
CVE-2025-50971
was published
Aug 26, 2025
xml2rfc has an arbitrary file read vulnerability
High
GHSA-cfmv-h8fx-85m7
was published
for
xml2rfc
(pip)
Aug 26, 2025
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the...
Critical
Unreviewed
CVE-2025-55526
was published
Aug 26, 2025
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function...
Moderate
Unreviewed
CVE-2025-9409
was published
Aug 26, 2025
A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor...
Critical
Unreviewed
CVE-2025-53120
was published
Aug 26, 2025
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
High
Unreviewed
CVE-2025-29420
was published
Aug 26, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8562
was published
Aug 25, 2025
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform...
Critical
Unreviewed
CVE-2025-9118
was published
Aug 25, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-52450
was published
Aug 22, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
In MindManager Windows versions prior to 24.1.150, attackers could potentially write to...
High
Unreviewed
CVE-2024-56179
was published
Aug 22, 2025
Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall...
High
Unreviewed
CVE-2010-20109
was published
Aug 21, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to...
Low
Unreviewed
CVE-2025-55523
was published
Aug 21, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing...
Critical
Unreviewed
CVE-2025-8895
was published
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a...
Moderate
Unreviewed
CVE-2025-53505
was published
Aug 21, 2025
Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows...
High
Unreviewed
CVE-2012-10061
was published
Aug 20, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-54926
was published
Aug 20, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2025-54927
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API