GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
283 advisories
Filter by severity
Arbitrary file deletion in ureport
Critical
CVE-2023-24188
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 13, 2023
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
Moderate
CVE-2023-24815
was published
for
io.vertx:vertx-web
(Maven)
Feb 10, 2023
Path Traversal In Eclipse GlassFish
Moderate
CVE-2022-2712
was published
for
org.glassfish.main.web:web
(Maven)
Jan 27, 2023
Path Traversal in Jenkins visualexpert Plugin
Moderate
CVE-2023-24455
was published
for
io.jenkins.plugins:visualexpert
(Maven)
Jan 26, 2023
Path traversal vulnerability in Jenkins PWauth Security Realm Plugin
Moderate
CVE-2023-24449
was published
for
org.jvnet.hudson.plugins:pwauth
(Maven)
Jan 26, 2023
MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
Critical
CVE-2023-24057
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Jan 23, 2023
org.neo4j.procedure:apoc Path Traversal Vulnerability
High
CVE-2022-23532
was published
for
org.neo4j.procedure:apoc
(Maven)
Jan 13, 2023
Gravitee API Management contains Path Traversal
High
CVE-2022-38723
was published
for
io.gravitee.apim:gravitee-api-management
(Maven)
Jan 4, 2023
Path Traversal In MeterSpere leads to upload file to any path
High
CVE-2022-46178
was published
for
io.metersphere:metersphere
(Maven)
Dec 30, 2022
Widoco Path Traversal vulnerability
High
CVE-2022-4772
was published
for
com.github.dgarijo:Widoco
(Maven)
Dec 28, 2022
SCIFIO vulnerable to Path Traversal
Critical
CVE-2022-4493
was published
for
io.scif:scifio
(Maven)
Dec 14, 2022
Apache Atlas: zip path traversal in import functionality
High
CVE-2022-34271
was published
for
org.apache.atlas:apache-atlas
(Maven)
Dec 14, 2022
Keycloak vulnerable to path traversal via double URL encoding
Critical
CVE-2022-3782
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 13, 2022
FusionAuth vulnerable to directory traversal attack
High
CVE-2022-45921
was published
for
io.fusionauth:fusionauth-java-client
(Maven)
Nov 28, 2022
TestNG is vulnerable to Path Traversal
High
CVE-2022-4065
was published
for
org.testng:testng
(Maven)
Nov 19, 2022
Jenkins Config Rotator Plugin vulnerable to path traversal
High
CVE-2022-45388
was published
for
org.jenkins-ci.main:config-rotator
(Maven)
Nov 16, 2022
Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin
High
CVE-2022-45381
was published
for
org.jenkins-ci.plugins:pipeline-utility-steps
(Maven)
Nov 16, 2022
Path Traversal in Liferay Portal
High
CVE-2022-42123
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Path Traversal in Liferay Portal
High
CVE-2022-42125
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Apache Ivy vulnerable to path traversal
High
CVE-2022-37866
was published
for
org.apache.ivy:ivy
(Maven)
Nov 7, 2022
Apache Ivy does not verify target path when extracting the archive
Critical
CVE-2022-37865
was published
for
org.apache.ivy:ivy
(Maven)
Nov 7, 2022
Apache UIMA Path Traversal vulnerability
High
CVE-2022-32287
was published
for
org.apache.uima:uimaj-core
(Maven)
Nov 3, 2022
Apache DolphinScheduler vulnerable to Path Traversal
Moderate
CVE-2022-34662
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Nov 1, 2022
Apache DolphinScheduler vulnerable to Path Traversal
Moderate
CVE-2022-26884
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Oct 28, 2022
Liferay Portal Path Traversal Vulnerability via the Hypermedia REST APIs Module
High
CVE-2022-28981
was published
for
com.liferay:com.liferay.headless.discovery.web
(Maven)
Sep 23, 2022
ProTip!
Advisories are also available from the
GraphQL API