GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
21 advisories
Filter by severity
The Woocommerce Blocks – Woolook plugin for WordPress is vulnerable to Local File Inclusion in...
Moderate
Unreviewed
CVE-2024-8393
was published
Aug 16, 2025
A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote...
Moderate
Unreviewed
CVE-2025-51057
was published
Aug 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-54015
was published
Jul 16, 2025
A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender...
Moderate
Unreviewed
CVE-2024-40112
was published
Jun 2, 2025
Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain...
Moderate
Unreviewed
CVE-2025-25539
was published
May 21, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-32499
was published
Apr 9, 2025
Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing...
Moderate
Unreviewed
CVE-2023-49031
was published
Mar 3, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-24782
was published
Jan 27, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-24733
was published
Jan 24, 2025
IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload...
Moderate
Unreviewed
CVE-2024-45077
was published
Jan 24, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-22305
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-56216
was published
Dec 31, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-52385
was published
Dec 9, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-52386
was published
Nov 17, 2024
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel,...
Moderate
Unreviewed
CVE-2024-4359
was published
Aug 12, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-35650
was published
Jun 10, 2024
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the...
Moderate
Unreviewed
CVE-2024-34314
was published
May 7, 2024
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704....
Moderate
Unreviewed
CVE-2024-0315
was published
Jan 15, 2024
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to...
Moderate
Unreviewed
CVE-2023-23565
was published
Aug 22, 2023
Local File read vulnerability in OctoberCMS
Moderate
CVE-2020-5295
was published
for
october/cms
(Composer)
Jun 3, 2020
ProTip!
Advisories are also available from the
GraphQL API