GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,491 advisories
Filter by severity
Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup...
High
Unreviewed
CVE-2023-53907
was published
Dec 18, 2025
mcp-server-git has missing path validation when using --repository flag
Moderate
CVE-2025-68145
was published
for
mcp-server-git
(pip)
Dec 17, 2025
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to...
High
Unreviewed
CVE-2025-67171
was published
Dec 17, 2025
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
Moderate
CVE-2025-68143
was published
for
mcp-server-git
(pip)
Dec 17, 2025
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation...
High
Unreviewed
CVE-2025-14727
was published
Dec 17, 2025
The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all...
Moderate
Unreviewed
CVE-2025-12496
was published
Dec 17, 2025
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
High
CVE-2025-68155
was published
for
@vitejs/plugin-rsc
(npm)
Dec 16, 2025
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an...
Critical
Unreviewed
CVE-2025-63414
was published
Dec 16, 2025
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated...
High
Unreviewed
CVE-2023-53902
was published
Dec 16, 2025
WaveView client allows users to execute restricted set of predefined commands and scripts on the...
High
Unreviewed
CVE-2025-65074
was published
Dec 16, 2025
WaveView client allows users to execute restricted set of predefined commands and scripts on the...
Moderate
Unreviewed
CVE-2025-65075
was published
Dec 16, 2025
WaveView client allows users to execute restricted set of predefined commands and scripts on the...
High
Unreviewed
CVE-2025-65076
was published
Dec 16, 2025
A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows...
High
Unreviewed
CVE-2025-60786
was published
Dec 15, 2025
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its...
High
Unreviewed
CVE-2025-34181
was published
Dec 15, 2025
A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-14702
was published
Dec 15, 2025
A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown...
Moderate
Unreviewed
CVE-2025-14704
was published
Dec 15, 2025
A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This...
Moderate
Unreviewed
CVE-2025-14698
was published
Dec 15, 2025
A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This...
Moderate
Unreviewed
CVE-2025-14699
was published
Dec 15, 2025
A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android....
Moderate
Unreviewed
CVE-2025-14617
was published
Dec 13, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Low
Unreviewed
CVE-2025-43465
was published
Dec 12, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Moderate
Unreviewed
CVE-2025-43463
was published
Dec 12, 2025
Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip
High
CVE-2025-67818
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
Weaviate OSS has path traversal vulnerability via the Shard Movement API
High
CVE-2025-67819
was published
for
github.com/weaviate/weaviate
(Go)
Dec 12, 2025
The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up...
Moderate
Unreviewed
CVE-2025-12960
was published
Dec 12, 2025
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path...
Moderate
Unreviewed
CVE-2025-13891
was published
Dec 12, 2025
ProTip!
Advisories are also available from the
GraphQL API