GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,014 advisories
Filter by severity
Directory traversal in Rack::Directory app bundled with Rack
High
CVE-2020-8161
was published
for
rack
(RubyGems)
Jul 6, 2020
Directory traversal attack in Spring Cloud Config
High
CVE-2020-5410
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
Jun 5, 2020
Cross-Site Scripting in http_server
High
CVE-2019-15600
was published
for
http_server
(npm)
Mar 31, 2020
Relative Path Traversal (CWE-23) in chunked uploads in oneup/uploader-bundle
High
CVE-2020-5237
was published
for
oneup/uploader-bundle
(Composer)
Feb 18, 2020
npm Vulnerable to Global node_modules Binary Overwrite
High
CVE-2019-16777
was published
for
npm
(npm)
Dec 13, 2019
npm symlink reference outside of node_modules
High
CVE-2019-16776
was published
for
npm
(npm)
Dec 13, 2019
Arbitrary File Write in iobroker.js-controller
High
CVE-2019-10767
was published
for
iobroker.js-controller
(npm)
Dec 2, 2019
Path traversal attack on Windows platforms
High
CVE-2019-0207
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Nov 18, 2019
Path Traversal in LibreNMS
High
CVE-2019-12464
was published
for
librenms/librenms
(Composer)
Oct 11, 2019
Symlink Arbitrary File Overwrite in bower
High
CVE-2019-5484
was published
for
bower
(npm)
Sep 17, 2019
Path Traversal in algo-httpserv
High
GHSA-cgjv-rghq-qhgp
was published
for
algo-httpserv
(npm)
Sep 11, 2019
Path Traversal in serve-here.js
High
GHSA-g8m7-qhv7-9h5x
was published
for
serve-here
(npm)
Jul 5, 2019
Path Traversal vulnerability that affects yard
High
CVE-2019-1020001
was published
for
yard
(RubyGems)
Jul 2, 2019
RubyGems Delete directory using symlink when decompressing tar
High
CVE-2019-8320
was published
for
rubygems-update
(RubyGems)
Jun 20, 2019
Directory Traversal in lactate
High
GHSA-68gr-cmcp-g3mj
was published
for
lactate
(npm)
Jun 14, 2019
Path Traversal in localhost-now
High
GHSA-73cw-jxmm-qpgh
was published
for
localhost-now
(npm)
Jun 11, 2019
High severity vulnerability that affects gun
High
GHSA-886v-mm6p-4m66
was published
for
gun
(npm)
Jun 5, 2019
Path Traversal in angular-http-server
High
GHSA-vmhw-fhj6-m3g5
was published
for
angular-http-server
(npm)
May 31, 2019
Path Traversal in DKPro Core
High
CVE-2019-11082
was published
for
de.tudarmstadt.ukp.dkpro.core:de.tudarmstadt.ukp.dkpro.core.api.datasets-asl
(Maven)
May 29, 2019
Path Traversal in Apache Camel
High
CVE-2019-0194
was published
for
org.apache.camel:camel-core
(Maven)
May 2, 2019
Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-war
High
CVE-2019-0225
was published
for
org.apache.jspwiki:jspwiki-war
(Maven)
Apr 8, 2019
Path Traversal in http-live-simulator
High
CVE-2019-5423
was published
for
http-live-simulator
(npm)
Apr 8, 2019
ProTip!
Advisories are also available from the
GraphQL API