GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
6,843 advisories
Filter by severity
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as...
Moderate
Unreviewed
CVE-2025-5714
was published
Jun 6, 2025
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-3055
was published
Jun 5, 2025
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows...
Moderate
Unreviewed
CVE-2025-20259
was published
Jun 4, 2025
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an...
Low
Unreviewed
CVE-2025-20277
was published
Jun 4, 2025
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5....
Moderate
Unreviewed
CVE-2025-5544
was published
Jun 4, 2025
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to...
Moderate
Unreviewed
CVE-2025-5545
was published
Jun 4, 2025
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This...
Moderate
Unreviewed
CVE-2025-5509
was published
Jun 3, 2025
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions ...
Critical
Unreviewed
CVE-2024-12718
was published
Jun 3, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4330
was published
Jun 3, 2025
Allows the extraction filter to be ignored, allowing symlink targets to point outside the...
High
Unreviewed
CVE-2025-4138
was published
Jun 3, 2025
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter...
Critical
Unreviewed
CVE-2025-4517
was published
Jun 3, 2025
A directory traversal vulnerability exists in the PVMP package unpacking functionality of...
High
Unreviewed
CVE-2025-31359
was published
Jun 3, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
Moderate
Unreviewed
CVE-2025-41428
was published
Jun 3, 2025
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain...
High
Unreviewed
CVE-2025-27956
was published
Jun 2, 2025
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Moderate
Unreviewed
CVE-2025-37095
was published
Jun 2, 2025
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
Moderate
Unreviewed
CVE-2025-37094
was published
Jun 2, 2025
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from...
Moderate
Unreviewed
CVE-2025-33004
was published
Jun 1, 2025
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5385
was published
May 31, 2025
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2....
Moderate
Unreviewed
CVE-2025-5381
was published
May 31, 2025
A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu...
Moderate
Unreviewed
CVE-2025-5380
was published
May 31, 2025
The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2025-4857
was published
May 31, 2025
A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5328
was published
May 29, 2025
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse...
Moderate
Unreviewed
CVE-2024-51453
was published
May 28, 2025
Traefik allows path traversal using url encoding
Low
CVE-2025-47952
was published
for
github.com/traefik/traefik
(Go)
May 28, 2025
ProTip!
Advisories are also available from the
GraphQL API