GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,168
Erlang
30
GitHub Actions
19
Go
1,975
Maven
5,000+
npm
3,698
NuGet
654
pip
3,314
Pub
11
RubyGems
882
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
533 advisories
Filter by severity
Path traversal in ZIPFoundation
High
CVE-2023-39138
was published
for
github.com/weichsel/ZIPFoundation
(Swift)
Aug 31, 2023
Path traversal in Zip Swift
High
CVE-2023-39135
was published
for
github.com/marmelroy/Zip
(Swift)
Aug 31, 2023
pf4j vulnerable to remote code execution via the zippluginPath parameter
High
CVE-2023-40826
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via loadpluginPath parameter
High
CVE-2023-40827
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
pf4j vulnerable to remote code execution via expandIfZip method in the extract function
High
CVE-2023-40828
was published
for
org.pf4j:pf4j
(Maven)
Aug 29, 2023
webui-aria2 Path Traversal vulnerability
High
CVE-2023-39141
was published
for
webui-aria2
(npm)
Aug 22, 2023
1Panel O&M management panel has a background arbitrary file reading vulnerability
High
CVE-2023-39964
was published
for
github.com/1Panel-dev/1Panel
(Go)
Aug 10, 2023
Nuclei Path Traversal vulnerability
High
CVE-2023-37896
was published
for
github.com/projectdiscovery/nuclei
(Go)
Aug 4, 2023
Arbitrary File Creation in AbstractUnArchiver
High
CVE-2023-37460
was published
for
org.codehaus.plexus:plexus-archiver
(Maven)
Jul 25, 2023
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
High
CVE-2023-38337
was published
for
rswag
(RubyGems)
Jul 15, 2023
copyparty vulnerable to path traversal attack
High
CVE-2023-37474
was published
for
copyparty
(pip)
Jul 14, 2023
ethyca-fides Webserver API Path Traversal vulnerability
High
CVE-2023-36827
was published
for
ethyca-fides
(pip)
Jul 6, 2023
elFinder vulnerable to path traversal in LocalVolumeDriver connector
High
CVE-2023-35840
was published
for
studio-42/elfinder
(Composer)
Jun 14, 2023
Froxlor vulnerable to Path Traversal
High
CVE-2023-3172
was published
for
froxlor/froxlor
(Composer)
Jun 9, 2023
Duplicate Advisory: Starlette vulnerable to directory traversal
High
GHSA-qj8w-rv5x-2v9h
was published
for
starlette
(pip)
Jun 1, 2023
•
withdrawn
Administration Console authentication bypass in openfire xmppserver
High
CVE-2023-32315
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
May 23, 2023
Any file can be included with the pymdown-snippets extension
High
CVE-2023-32309
was published
for
pymdown-extensions
(pip)
May 15, 2023
mflow vulnerable to directory traversal
High
CVE-2023-30172
was published
for
mlflow
(pip)
May 11, 2023
m.static Directory Traversal vulnerability
High
CVE-2023-26126
was published
for
m.static
(npm)
May 10, 2023
Path traversal vulnerability in the file manager
High
CVE-2023-29200
was published
for
contao/contao
(Composer)
Apr 26, 2023
Directory traversal + file write causing arbitrary code execution
High
CVE-2023-30626
was published
for
Jellyfin.Controller
(NuGet)
Apr 24, 2023
pretalx vulnerable to path traversal in HTML export
High
CVE-2023-28459
was published
for
pretalx
(pip)
Apr 20, 2023
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
High
CVE-2023-30620
was published
for
mindsdb
(pip)
Mar 30, 2023
ProTip!
Advisories are also available from the
GraphQL API