GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,851
Erlang
36
GitHub Actions
35
Go
2,481
Maven
5,000+
npm
4,098
NuGet
734
pip
3,914
Pub
12
RubyGems
945
Rust
1,016
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,149 advisories
Filter by severity
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-7975
was published
Sep 2, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Moderate
CVE-2025-58162
was published
for
mobsf
(pip)
Sep 2, 2025
A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an...
High
Unreviewed
CVE-2025-52861
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30270
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30271
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-33032
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33036
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33033
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33037
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33038
was published
Aug 29, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3...
Moderate
Unreviewed
CVE-2025-9650
was published
Aug 29, 2025
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2025-9217
was published
Aug 29, 2025
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an...
High
Unreviewed
CVE-2024-13986
was published
Aug 28, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-53588
was published
Aug 28, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54029
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-58072
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-54819
was published
Aug 28, 2025
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path...
Moderate
Unreviewed
CVE-2025-9345
was published
Aug 28, 2025
QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path...
Critical
Unreviewed
CVE-2024-13984
was published
Aug 28, 2025
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform ...
Critical
Unreviewed
CVE-2023-7309
was published
Aug 28, 2025
LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co....
Critical
Unreviewed
CVE-2024-13981
was published
Aug 28, 2025
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON...
High
Unreviewed
CVE-2024-13982
was published
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API