GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
6,939 advisories
Filter by severity
The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all...
High
Unreviewed
CVE-2024-10516
was published
Dec 6, 2024
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-11010
was published
Dec 7, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-53790
was published
Dec 9, 2024
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal...
High
Unreviewed
CVE-2024-50626
was published
Dec 10, 2024
The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path,...
Moderate
Unreviewed
CVE-2024-10708
was published
Dec 10, 2024
luigi Arbitrary File Write via Archive Extraction (Zip Slip)
High
CVE-2024-21542
was published
for
luigi
(pip)
Dec 10, 2024
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory...
High
Unreviewed
CVE-2023-6947
was published
Dec 10, 2024
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2024-45709
was published
Dec 10, 2024
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative...
Moderate
Unreviewed
CVE-2024-55550
was published
Dec 10, 2024
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
SiYuan has an arbitrary file write in the host via /api/asset/upload
High
CVE-2024-55659
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic....
Moderate
Unreviewed
CVE-2024-12482
was published
Dec 12, 2024
Windows File Explorer Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49082
was published
Dec 12, 2024
python-libarchive directory traversal
High
CVE-2024-55587
was published
for
python-libarchive
(pip)
Dec 12, 2024
A path handling issue was addressed with improved validation. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-54489
was published
Dec 12, 2024
An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to...
Moderate
Unreviewed
CVE-2024-8647
was published
Dec 12, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-11834
was published
Dec 13, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-11833
was published
Dec 13, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-54259
was published
Dec 13, 2024
File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue...
High
Unreviewed
CVE-2024-55970
was published
Dec 15, 2024
A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-12362
was published
Dec 16, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-54380
was published
Dec 16, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-54374
was published
Dec 16, 2024
ProTip!
Advisories are also available from the
GraphQL API