GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
215 advisories
Filter by severity
The go command may execute unexpected commands when operating in untrusted VCS repositories. This...
High
Unreviewed
CVE-2025-4674
was published
Jul 30, 2025
: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows :...
High
Unreviewed
CVE-2025-29866
was published
Aug 7, 2025
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-53769
was published
Aug 12, 2025
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows...
High
Unreviewed
CVE-2011-10030
was published
Aug 20, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20269
was published
Aug 20, 2025
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
Critical
CVE-2025-55746
was published
for
@directus/api
(npm)
Aug 20, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-9048
was published
Aug 23, 2025
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element...
Moderate
Unreviewed
CVE-2025-9529
was published
Aug 27, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous...
Low
Unreviewed
CVE-2025-10043
was published
Sep 5, 2025
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2025-10134
was published
Sep 9, 2025
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts...
Moderate
Unreviewed
CVE-2025-9920
was published
Sep 9, 2025
External control of file name or path in Azure Arc allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-55316
was published
Sep 9, 2025
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-8422
was published
Sep 11, 2025
ProTip!
Advisories are also available from the
GraphQL API