GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,395
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,069 advisories
Filter by severity
The number identification module has a path traversal vulnerability. Successful exploitation of...
High
Unreviewed
CVE-2022-39001
was published
Sep 17, 2022
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4138
was published
Jun 3, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4330
was published
Jun 3, 2025
Improper handling of input variables lead to multiple path traversal vulnerabilities in the...
High
Unreviewed
CVE-2025-22205
was published
Feb 4, 2025
Arbitrary file read vulnerability in Git server Plugin can lead to RCE
High
CVE-2024-23899
was published
for
org.jenkins-ci.plugins:git-server
(Maven)
Jan 24, 2024
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-3055
was published
Jun 5, 2025
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker...
High
Unreviewed
CVE-2025-33035
was published
Jun 6, 2025
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-3485
was published
Jun 6, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31050
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-39473
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31635
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48124
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48130
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48267
was published
Jun 9, 2025
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient...
High
Unreviewed
CVE-2025-42977
was published
Jun 10, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-5740
was published
Jun 10, 2025
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose...
High
Unreviewed
CVE-2025-37100
was published
Jun 10, 2025
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-47176
was published
Jun 10, 2025
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
High
CVE-2025-47273
was published
for
setuptools
(pip)
May 19, 2025
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows...
High
Unreviewed
CVE-2025-5964
was published
Jun 15, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-49415
was published
Jun 17, 2025
ProTip!
Advisories are also available from the
GraphQL API