GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,353
Maven
5,000+
npm
3,977
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
584 advisories
Filter by severity
DotVVM allows path traversal when deployed in Debug mode
High
GHSA-6q65-j4jw-9cg8
was published
for
DotVVM
(NuGet)
Jun 19, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
High
CVE-2025-47273
was published
for
setuptools
(pip)
May 19, 2025
Traefik has a possible vulnerability with the path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Yeswiki Path Traversal vulnerability allows arbitrary read of files
High
CVE-2025-31131
was published
for
yeswiki/yeswiki
(Composer)
Apr 1, 2025
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
High
CVE-2024-12905
was published
for
tar-fs
(npm)
Mar 27, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High
CVE-2024-8859
was published
for
mlflow
(pip)
Mar 20, 2025
AgentScope Path Traversal in /api/file
High
CVE-2024-8438
was published
for
agentscope
(pip)
Mar 20, 2025
AgentScope directory traversal vulnerability in /read-examples
High
CVE-2024-8524
was published
for
agentscope
(pip)
Mar 20, 2025
Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
High
CVE-2024-7776
was published
for
onnx
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
High
CVE-2025-29787
was published
for
zip
(Rust)
Mar 17, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
GHSA-w7f9-wqc4-3wxr
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
Label Studio has a Path Traversal Vulnerability via image Field
High
CVE-2025-25295
was published
for
label-studio-sdk
(pip)
Feb 14, 2025
Adobe Commerce Path Traversal
High
CVE-2025-24406
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
DevDojo Voyager vulnerable to path traversal
High
CVE-2024-55415
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Authenticated arbitrary file deletion in YesWiki
High
CVE-2025-24019
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API