GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,206 advisories
Filter by severity
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
Critical
CVE-2025-28384
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to directory traversal attack in minion file cache creation
Moderate
CVE-2025-22238
was published
for
salt
(pip)
Jun 13, 2025
Salt allows arbitrary directory creation or file deletion
Moderate
CVE-2025-22240
was published
for
salt
(pip)
Jun 13, 2025
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
Traefik allows path traversal using url encoding
Low
CVE-2025-47952
was published
for
github.com/traefik/traefik
(Go)
May 28, 2025
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
High
CVE-2025-47273
was published
for
setuptools
(pip)
May 19, 2025
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Moderate
CVE-2025-30159
was published
for
getkirby/kirby
(Composer)
May 13, 2025
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
CVE-2025-30207
was published
for
getkirby/cms
(Composer)
May 13, 2025
Kirby vulnerable to path traversal of collection names during file system lookup
Moderate
CVE-2025-31493
was published
for
getkirby/cms
(Composer)
May 13, 2025
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
Vite's server.fs.deny bypassed with /. for files under project root
Moderate
CVE-2025-46565
was published
for
vite
(npm)
Apr 30, 2025
io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage
Moderate
CVE-2025-32950
was published
for
io.jmix.localfs:jmix-localfs
(Maven)
Apr 22, 2025
Traefik has a possible vulnerability with the path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
Low
GHSA-2cvj-g5r5-jrrg
was published
for
surrealdb
(Rust)
Apr 10, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Yeswiki Path Traversal vulnerability allows arbitrary read of files
High
CVE-2025-31131
was published
for
yeswiki/yeswiki
(Composer)
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API