GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,091 advisories
Filter by severity
Path Traversal in jsreport-chrome-pdf
Moderate
CVE-2020-7762
was published
for
jsreport-chrome-pdf
(npm)
Apr 13, 2021
Path Traversal within joomla/archive zip class
Moderate
CVE-2021-26028
was published
for
joomla/archive
(Composer)
Mar 24, 2021
Django Directory Traversal via archive.extract
Moderate
CVE-2021-3281
was published
for
django
(pip)
Mar 18, 2021
Mautic users able to download any files from server using filemanager
Moderate
CVE-2017-1000490
was published
for
mautic/core
(Composer)
Jan 19, 2021
MPXJ path Traversal vulnerability
Moderate
CVE-2020-35460
was published
for
net.sf.mpxj:mpxj
(Maven)
Dec 18, 2020
Directory Traversal in featurebook
Moderate
GHSA-7x92-2j68-h32c
was published
for
featurebook
(npm)
Sep 1, 2020
Hidden Directories Always Served in inert
Moderate
CVE-2014-10068
was published
for
inert
(npm)
Aug 31, 2020
Directory traversal in Apache RocketMQ
Moderate
CVE-2019-17572
was published
for
org.apache.rocketmq:rocketmq-broker
(Maven)
Jul 1, 2020
Directory traversal outside of SENDFILE_ROOT in django-sendfile2
Moderate
GHSA-6r3c-8xf3-ggrr
was published
for
django-sendfile2
(pip)
Jun 24, 2020
Directory traversal attack in Spring Cloud Config
Moderate
CVE-2020-5405
was published
for
org.springframework.cloud:spring-cloud-config-server
(Maven)
Jun 5, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7652
was published
for
snyk-broker
(npm)
Jun 3, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7648
was published
for
snyk-broker
(npm)
Jun 3, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7650
was published
for
snyk-broker
(npm)
Jun 3, 2020
Arbitrary File Read in Snyk Broker
Moderate
CVE-2020-7651
was published
for
snyk-broker
(npm)
Jun 3, 2020
path traversal in Jooby
Moderate
CVE-2020-7647
was published
for
io.jooby:jooby
(Maven)
May 13, 2020
Path Traversal in statics-server
Moderate
CVE-2019-15596
was published
for
statics-server
(npm)
Mar 31, 2020
The rack-cors rubygem may allow directory traveral
Moderate
CVE-2019-18978
was published
for
rack-cors
(RubyGems)
Nov 15, 2019
Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms
Moderate
CVE-2019-13237
was published
for
org.opencms:opencms-core
(Maven)
Nov 12, 2019
Directory Traversal in SharpCompress
Moderate
CVE-2018-1002206
was published
for
sharpcompress
(NuGet)
Sep 11, 2019
Path Traversal in statichttpserver
Moderate
CVE-2019-5480
was published
for
statichttpserver
(npm)
Sep 4, 2019
ProTip!
Advisories are also available from the
GraphQL API