GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,222 advisories
Filter by severity
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2....
Moderate
Unreviewed
CVE-2025-11337
was published
Oct 6, 2025
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization...
Moderate
Unreviewed
CVE-2025-11336
was published
Oct 6, 2025
A remote, unauthorized attacker can brute force folders and files and read them like private keys...
Moderate
Unreviewed
CVE-2025-58591
was published
Oct 6, 2025
It's possible to brute force folders and files, what can be used by an attacker to steal sensitve...
Moderate
Unreviewed
CVE-2025-58590
was published
Oct 6, 2025
clearml is vulnerable to Path Traversal through its `safe_extract` function
Moderate
CVE-2025-8917
was published
for
clearml
(pip)
Oct 5, 2025
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
Moderate
CVE-2025-8406
was published
for
zenml
(pip)
Oct 5, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-47211
was published
Oct 3, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
Moderate
Unreviewed
CVE-2025-33034
was published
Oct 3, 2025
The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8559
was published
Sep 30, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function...
Moderate
Unreviewed
CVE-2025-11139
was published
Sep 29, 2025
A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-11079
was published
Sep 27, 2025
A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element...
Moderate
Unreviewed
CVE-2025-11034
was published
Sep 26, 2025
A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2025-11031
was published
Sep 26, 2025
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected...
Moderate
Unreviewed
CVE-2025-11016
was published
Sep 26, 2025
A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects...
Moderate
Unreviewed
CVE-2025-11018
was published
Sep 26, 2025
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-10307
was published
Sep 26, 2025
ml-logger has path traversal in the file argument
Moderate
CVE-2025-10951
was published
for
ml-logger
(pip)
Sep 25, 2025
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10777
was published
Sep 22, 2025
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10766
was published
Sep 22, 2025
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers...
Moderate
Unreviewed
CVE-2025-56869
was published
Sep 22, 2025
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to...
Moderate
Unreviewed
CVE-2025-57682
was published
Sep 22, 2025
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization...
Moderate
Unreviewed
CVE-2025-10708
was published
Sep 19, 2025
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0....
Moderate
Unreviewed
CVE-2025-10709
was published
Sep 19, 2025
ProTip!
Advisories are also available from the
GraphQL API