GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,973
NuGet
715
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
263 advisories
Filter by severity
Erupt Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2025-45855
was published
for
xyz.erupt:erupt
(Maven)
Jun 3, 2025
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Moderate
CVE-2025-48953
was published
for
Umbraco.Cms
(NuGet)
Jun 4, 2025
Gradio Allows Unauthorized File Copy via Path Manipulation
Moderate
CVE-2025-48889
was published
for
gradio
(pip)
May 29, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
October CMS Allows Unprotected SVG Rename in Media Manager
Low
CVE-2024-51991
was published
for
october/october
(Composer)
May 5, 2025
TYPO3 Allows Unrestricted File Upload in File Abstraction Layer
Moderate
CVE-2025-47939
was published
for
typo3/cms-core
(Composer)
May 20, 2025
Connect-Multiparty allows arbitrary file upload
High
CVE-2022-29623
was published
for
connect-multiparty
(npm)
May 17, 2022
ShowDoc unrestricted file upload vulnerability
Critical
CVE-2025-0520
was published
for
showdoc/showdoc
(Composer)
Apr 29, 2025
Badaso vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-41705
was published
for
badaso/core
(Composer)
Nov 25, 2022
MODX Revolution allows overwriting .htaccess
High
CVE-2017-9069
was published
for
modx/revolution
(Composer)
May 17, 2022
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low
CVE-2024-45965
was published
for
contao/contao
(Composer)
Oct 2, 2024
•
withdrawn
MCMS allows arbitrary file uploads in the ueditor component
Critical
CVE-2025-29287
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 21, 2025
TYPO3 doesn't properly check file extensions
High
CVE-2013-4250
was published
for
typo3/cms
(Composer)
May 17, 2022
Unrestricted file upload in kiwi TCMS
High
CVE-2023-30613
was published
for
kiwitcms
(pip)
Apr 24, 2023
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
PyTorch Lightning path traversal vulnerability
Critical
CVE-2024-8019
was published
for
pytorch-lightning
(pip)
Mar 20, 2025
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
High
CVE-2024-8060
was published
for
open-webui
(pip)
Mar 20, 2025
DB-GPT Arbitrary File Write vulnerability
Critical
CVE-2024-10901
was published
for
dbgpt
(pip)
Mar 20, 2025
Flowise Pre-auth Arbitrary File Upload
Critical
GHSA-h42x-xx2q-6v6g
was published
for
flowise
(npm)
Mar 13, 2025
REDAXO allows Arbitrary File Upload in the mediapool page
Moderate
CVE-2025-27411
was published
for
redaxo/source
(Composer)
Mar 5, 2025
FlowiseAI Flowise arbitrary file upload vulnerability
High
CVE-2025-26319
was published
for
flowise
(npm)
Mar 5, 2025
Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets
High
CVE-2023-50386
was published
for
org.apache.solr:solr-core
(Maven)
Feb 9, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability
High
CVE-2024-22393
was published
for
github.com/apache/incubator-answer
(Go)
Feb 22, 2024
Uvdesk remote code execution vulnerability
High
CVE-2023-0265
was published
for
uvdesk/community-skeleton
(Composer)
Apr 5, 2023
Magento 2 Community Edition RCE via Unsafe File Upload
Critical
CVE-2020-24407
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API