GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,091 advisories
Filter by severity
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30271
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-33032
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30270
was published
Aug 29, 2025
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3...
Moderate
Unreviewed
CVE-2025-9650
was published
Aug 29, 2025
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2025-9217
was published
Aug 29, 2025
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5174
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5345
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path...
Moderate
Unreviewed
CVE-2025-9345
was published
Aug 28, 2025
A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an...
Moderate
Unreviewed
CVE-2025-20344
was published
Aug 27, 2025
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack,...
Moderate
Unreviewed
CVE-2024-52885
was published
Aug 6, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-52450
was published
Aug 22, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function...
Moderate
Unreviewed
CVE-2025-9409
was published
Aug 26, 2025
The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8562
was published
Aug 25, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a...
Moderate
Unreviewed
CVE-2025-53505
was published
Aug 21, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2025-54927
was published
Aug 20, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-47650
was published
Aug 20, 2025
Copier's safe template has filesystem write access outside destination path
Moderate
CVE-2025-55214
was published
for
copier
(pip)
Aug 18, 2025
Spring Framework MVC Applications Path Traversal Vulnerability
Moderate
CVE-2025-41242
was published
for
org.springframework:spring-webmvc
(Maven)
Aug 18, 2025
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised...
Moderate
Unreviewed
CVE-2021-21001
was published
May 24, 2022
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-54715
was published
Aug 14, 2025
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory...
Moderate
Unreviewed
CVE-2025-0818
was published
Aug 13, 2025
ProTip!
Advisories are also available from the
GraphQL API