GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
154 advisories
Filter by severity
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Low
Unreviewed
CVE-2024-37046
was published
Nov 22, 2024
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
Langchain-Chatchat has a Path Traversal vulnerability
Low
CVE-2025-6853
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to...
Low
Unreviewed
CVE-2025-55523
was published
Aug 21, 2025
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4....
Low
Unreviewed
CVE-2025-8522
was published
Aug 4, 2025
Upsonic is vulnerable to Path Traversal attack through its os.path.join function
Low
CVE-2025-6278
was published
for
upsonic
(pip)
Jun 19, 2025
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an...
Low
Unreviewed
CVE-2025-3722
was published
Jun 26, 2025
A path handling issue was addressed with improved validation. This issue is fixed in macOS...
Low
Unreviewed
CVE-2023-40383
was published
Jan 11, 2024
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an...
Low
Unreviewed
CVE-2025-20277
was published
Jun 4, 2025
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does...
Low
Unreviewed
CVE-2023-2252
was published
Jan 16, 2024
Traefik allows path traversal using url encoding
Low
CVE-2025-47952
was published
for
github.com/traefik/traefik
(Go)
May 28, 2025
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
Low
Unreviewed
CVE-2024-24940
was published
Feb 6, 2024
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
CVE-2025-30207
was published
for
getkirby/cms
(Composer)
May 13, 2025
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation...
Low
Unreviewed
CVE-2025-22479
was published
May 6, 2025
The Permission Model assumes that any path starting with two backslashes \ has a four-character...
Low
Unreviewed
CVE-2024-37372
was published
Jan 9, 2025
The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files...
Low
Unreviewed
CVE-2025-32943
was published
Apr 15, 2025
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users...
Low
Unreviewed
CVE-2014-8737
was published
May 17, 2022
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for...
Low
Unreviewed
CVE-2014-9461
was published
May 17, 2022
Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for...
Low
Unreviewed
CVE-2012-3380
was published
May 17, 2022
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3...
Low
Unreviewed
CVE-2010-0926
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API