GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,800
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,005
NuGet
720
pip
3,805
Pub
12
RubyGems
927
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
128 advisories
Filter by severity
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath.0 parameter
Moderate
CVE-2008-1301
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Alkacon OpenCMS Absolute Path Traversal via pathname in filePath parameter
Moderate
CVE-2006-3934
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
OpenRefine vulnerable to zip slip in project import
Moderate
CVE-2023-37476
was published
for
org.openrefine:main
(Maven)
Jul 18, 2023
Jenkins WildFly Deployer Plugin vulnerable to path traversal
Moderate
CVE-2022-41235
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
Sep 22, 2022
io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage
Moderate
CVE-2025-32950
was published
for
io.jmix.localfs:jmix-localfs
(Maven)
Apr 22, 2025
Apache DolphinScheduler vulnerable to Path Traversal
Moderate
CVE-2022-34662
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Nov 1, 2022
WSO2 Carbon directory traversal vulnerability
Moderate
CVE-2016-4314
was published
for
org.wso2.carbon.commons:org.wso2.carbon.logging.view.ui
(Maven)
May 14, 2022
Apache OpenMeetings Directory Traversal vulnerability
Moderate
CVE-2016-0784
was published
for
org.apache.openmeetings:openmeetings-install
(Maven)
May 14, 2022
Jenkins Image Gallery Plugin allows Path Traversal
Moderate
CVE-2016-4987
was published
for
com.tupilabs.image_gallery:image-gallery
(Maven)
May 13, 2022
Jenkins has Local File Inclusion Vulnerability
Moderate
CVE-2015-5322
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backends
Moderate
CVE-2025-24961
was published
for
org.gaul:s3proxy
(Maven)
Feb 3, 2025
Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability
Moderate
CVE-2024-54004
was published
for
aendter.jenkins.plugins:filesystem-list-parameter-plugin
(Maven)
Nov 27, 2024
FitNesse Path Traversal
Moderate
CVE-2024-42499
was published
for
org.fitnesse:fitnesse
(Maven)
Nov 15, 2024
Jenkins HTML Publisher Plugin Path traversal vulnerability
Moderate
CVE-2024-28151
was published
for
org.jenkins-ci.plugins:htmlpublisher
(Maven)
Mar 6, 2024
MPXJ has a Potential Path Traversal Vulnerability
Moderate
CVE-2024-49771
was published
for
MPXJ.Net
(RubyGems)
Oct 28, 2024
Absolute path traversal vulnerability in digdag server
Moderate
CVE-2024-25125
was published
for
io.digdag:digdag-server
(Maven)
Feb 14, 2024
CometVisu Backend for openHAB has a path traversal vulnerability
Moderate
CVE-2024-42468
was published
for
org.openhab.ui.bundles:org.openhab.ui.cometvisu
(Maven)
Aug 9, 2024
Apache Zeppelin Path Traversal vulnerability
Moderate
CVE-2024-31860
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
Path Traversal in Jenkins
Moderate
CVE-2018-1000406
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Path traversal in org.springframework.integration:spring-integration-zip
Moderate
CVE-2018-1261
was published
for
org.springframework.integration:spring-integration-zip
(Maven)
Oct 18, 2018
spring-integration-zip Arbitrary File Write
Moderate
CVE-2018-1263
was published
for
org.springframework.integration:spring-integration-zip
(Maven)
May 13, 2022
ZipSlip in org.apache.storm:storm-core
Moderate
CVE-2018-8008
was published
for
org.apache.storm:storm-core
(Maven)
Oct 16, 2018
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Moderate
CVE-2014-3578
was published
for
org.springframework:spring-core
(Maven)
May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Jenkins
Moderate
CVE-2019-10352
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API