GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,023 advisories
Filter by severity
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-5740
was published
Jun 10, 2025
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient...
High
Unreviewed
CVE-2025-42977
was published
Jun 10, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48130
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48124
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-48267
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31635
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-39473
was published
Jun 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-31050
was published
Jun 9, 2025
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-3485
was published
Jun 6, 2025
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker...
High
Unreviewed
CVE-2025-33035
was published
Jun 6, 2025
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-3055
was published
Jun 5, 2025
Arbitrary file read vulnerability in Git server Plugin can lead to RCE
High
CVE-2024-23899
was published
for
org.jenkins-ci.plugins:git-server
(Maven)
Jan 24, 2024
Improper handling of input variables lead to multiple path traversal vulnerabilities in the...
High
Unreviewed
CVE-2025-22205
was published
Feb 4, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4330
was published
Jun 3, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4138
was published
Jun 3, 2025
The number identification module has a path traversal vulnerability. Successful exploitation of...
High
Unreviewed
CVE-2022-39001
was published
Sep 17, 2022
Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path...
High
Unreviewed
CVE-2023-50916
was published
Jan 10, 2024
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it...
High
Unreviewed
CVE-2023-45722
was published
Jan 3, 2024
A directory traversal vulnerability exists in the PVMP package unpacking functionality of...
High
Unreviewed
CVE-2025-31359
was published
Jun 3, 2025
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain...
High
Unreviewed
CVE-2025-27956
was published
Jun 2, 2025
The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2025-4857
was published
May 31, 2025
An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing...
High
Unreviewed
CVE-2021-32016
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API