GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,073 advisories
Filter by severity
An attacker with authenticated and privileged access could modify the contents of a non-sensitive...
Moderate
Unreviewed
CVE-2025-48395
was published
Sep 5, 2025
In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of...
Moderate
Unreviewed
CVE-2025-48550
was published
Sep 4, 2025
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Moderate
CVE-2025-58162
was published
for
mobsf
(pip)
Sep 2, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30270
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-30271
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-33032
was published
Aug 29, 2025
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3...
Moderate
Unreviewed
CVE-2025-9650
was published
Aug 29, 2025
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2025-9217
was published
Aug 29, 2025
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5174
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5345
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path...
Moderate
Unreviewed
CVE-2025-9345
was published
Aug 28, 2025
A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an...
Moderate
Unreviewed
CVE-2025-20344
was published
Aug 27, 2025
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack,...
Moderate
Unreviewed
CVE-2024-52885
was published
Aug 6, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-52450
was published
Aug 22, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function...
Moderate
Unreviewed
CVE-2025-9409
was published
Aug 26, 2025
The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8562
was published
Aug 25, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a...
Moderate
Unreviewed
CVE-2025-53505
was published
Aug 21, 2025
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...
Moderate
Unreviewed
CVE-2025-54927
was published
Aug 20, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-47650
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API