GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
65 advisories
Filter by severity
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read...
Moderate
Unreviewed
CVE-2025-43919
was published
Apr 20, 2025
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read...
Moderate
Unreviewed
CVE-2025-47423
was published
May 7, 2025
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is...
High
Unreviewed
CVE-2025-48050
was published
May 15, 2025
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper...
Critical
Unreviewed
CVE-2025-27920
was published
May 5, 2025
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified...
Moderate
Unreviewed
CVE-2024-2318
was published
Mar 8, 2024
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement
High
GHSA-fv2p-qj5p-wqq4
was published
for
github.com/lf-edge/ekuiper
(Go)
Jul 3, 2025
An authenticated, read-only user can upload a file and perform a directory traversal to have the...
High
Unreviewed
CVE-2025-54769
was published
Jul 29, 2025
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
Moderate
Unreviewed
CVE-2025-44962
was published
Aug 4, 2025
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local...
Low
Unreviewed
CVE-2025-46094
was published
Aug 5, 2025
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with...
Moderate
Unreviewed
CVE-2025-45582
was published
Jul 11, 2025
Juju zip slip vulnerability via authenticated endpoint
High
CVE-2025-53513
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager...
Critical
Unreviewed
CVE-2022-38129
was published
Aug 11, 2022
In multiple locations, there is a possible Android/data access due to a path traversal error....
Moderate
Unreviewed
CVE-2025-26427
was published
Sep 4, 2025
Memos Vulnerable to Path Traversal via the CreateResource Endpoint
Moderate
CVE-2025-56760
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API