GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,493 advisories
Filter by severity
The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-13677
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
High
Unreviewed
CVE-2025-61811
was published
Dec 10, 2025
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers...
High
Unreviewed
CVE-2021-47724
was published
Dec 9, 2025
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53772
was published
Dec 9, 2025
HP System Event Utility and Omen Gaming Hub might allow execution of
certain files outside of...
Moderate
Unreviewed
CVE-2025-11531
was published
Dec 9, 2025
Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal')...
High
Unreviewed
CVE-2025-60024
was published
Dec 9, 2025
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1...
Moderate
Unreviewed
CVE-2025-65287
was published
Dec 9, 2025
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote...
High
Unreviewed
CVE-2025-13661
was published
Dec 9, 2025
Robocode vulnerable to Directory Traversal in recursivelyDelete Method
Critical
CVE-2025-14306
was published
for
net.sf.robocode:robocode.core
(Maven)
Dec 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-14311
was published
Dec 9, 2025
SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
High
GHSA-4r66-7rcv-x46x
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
High
CVE-2025-67488
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
High
CVE-2025-66645
was published
for
nicegui
(pip)
Dec 9, 2025
A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this...
Moderate
Unreviewed
CVE-2025-14224
was published
Dec 8, 2025
A security vulnerability has been detected in ORICO CD3510 1.9.12. This affects an unknown...
Moderate
Unreviewed
CVE-2025-14220
was published
Dec 8, 2025
A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability...
Moderate
Unreviewed
CVE-2025-14182
was published
Dec 7, 2025
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress...
Critical
Unreviewed
CVE-2025-13377
was published
Dec 6, 2025
A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android....
Low
Unreviewed
CVE-2025-14111
was published
Dec 6, 2025
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability....
High
Unreviewed
CVE-2025-65879
was published
Dec 5, 2025
The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The...
High
Unreviewed
CVE-2025-65878
was published
Dec 5, 2025
zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In...
High
Unreviewed
CVE-2025-65897
was published
Dec 5, 2025
Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on...
High
Unreviewed
CVE-2025-64057
was published
Dec 5, 2025
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from...
Moderate
Unreviewed
CVE-2016-20023
was published
Dec 5, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54160
was published
Dec 4, 2025
ComposioHQ has a directory traversal vulnerability
Moderate
CVE-2025-56427
was published
for
composio
(pip)
Dec 4, 2025
ProTip!
Advisories are also available from the
GraphQL API