GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
242 advisories
Filter by severity
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress...
Moderate
Unreviewed
CVE-2024-12875
was published
Dec 21, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27944
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import...
High
Unreviewed
CVE-2024-27945
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27943
was published
May 14, 2024
php-svg-lib lacks path validation on font through SVG inline styles
Moderate
CVE-2024-25117
was published
for
phenx/php-svg-lib
(Composer)
Feb 21, 2024
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local...
Moderate
Unreviewed
CVE-2025-0630
was published
Feb 4, 2025
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12267
was published
Jan 31, 2025
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File...
Moderate
Unreviewed
CVE-2024-12861
was published
Jan 30, 2025
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
High
CVE-2024-1603
was published
for
paddlepaddle
(pip)
Mar 23, 2024
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an...
Moderate
Unreviewed
CVE-2025-0105
was published
Jan 11, 2025
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-0211
was published
Jan 4, 2025
A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an...
Moderate
Unreviewed
CVE-2025-0202
was published
Jan 4, 2025
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2024-12066
was published
Dec 21, 2024
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows...
High
Unreviewed
CVE-2024-4230
was published
Dec 19, 2024
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and...
Moderate
Unreviewed
CVE-2024-12357
was published
Dec 9, 2024
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
Moderate
CVE-2024-10492
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
Duplicate Advisory: Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
Low
GHSA-6vrw-mpj8-3j59
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
•
withdrawn
Weblate vulnerable to improper sanitization of project backups
Low
CVE-2024-39303
was published
for
Weblate
(pip)
Jul 1, 2024
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
High
CVE-2019-14905
was published
for
ansible
(pip)
Apr 20, 2021
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file...
Low
Unreviewed
CVE-2024-10672
was published
Nov 12, 2024
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This...
Moderate
Unreviewed
CVE-2024-5823
was published
Oct 29, 2024
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all...
Moderate
Unreviewed
CVE-2023-5816
was published
Oct 30, 2024
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to...
Critical
Unreviewed
CVE-2024-28394
was published
Mar 20, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43581
was published
Oct 8, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43615
was published
Oct 8, 2024
ProTip!
Advisories are also available from the
GraphQL API