GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
174 advisories
Filter by severity
The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing...
High
Unreviewed
CVE-2025-9639
was published
Aug 29, 2025
An authorized remote attacker can access files and directories outside the intended web root,...
Moderate
Unreviewed
CVE-2021-4459
was published
Aug 27, 2025
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-8464
was published
Aug 16, 2025
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all...
Moderate
Unreviewed
CVE-2024-48892
was published
Aug 12, 2025
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiMail version 7.6.0...
Moderate
Unreviewed
CVE-2024-40588
was published
Aug 12, 2025
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-53779
was published
Aug 12, 2025
A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to...
Moderate
Unreviewed
CVE-2025-51052
was published
Aug 6, 2025
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete...
Moderate
Unreviewed
CVE-2025-53082
was published
Jul 29, 2025
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
High
Unreviewed
CVE-2025-54531
was published
Jul 28, 2025
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can...
High
Unreviewed
CVE-2025-54317
was published
Jul 20, 2025
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File...
High
Unreviewed
CVE-2025-7619
was published
Jul 14, 2025
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-48817
was published
Jul 8, 2025
The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing...
High
Unreviewed
CVE-2025-7146
was published
Jul 8, 2025
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a...
Critical
Unreviewed
CVE-2025-52207
was published
Jun 27, 2025
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated...
High
Unreviewed
CVE-2025-52922
was published
Jun 23, 2025
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions...
High
Unreviewed
CVE-2025-34510
was published
Jun 17, 2025
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to...
High
Unreviewed
CVE-2025-33112
was published
Jun 10, 2025
A missing protection against path traversal allows to access
any file on the server.
Critical
Unreviewed
CVE-2025-3365
was published
Jun 6, 2025
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path...
Moderate
Unreviewed
CVE-2025-49466
was published
Jun 5, 2025
Relative Path Traversal vulnerability in Themewinter Eventin allows Path Traversal.This issue...
High
Unreviewed
CVE-2025-47445
was published
May 14, 2025
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and...
Moderate
Unreviewed
CVE-2025-22859
was published
May 13, 2025
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS...
High
Unreviewed
CVE-2025-24350
was published
Apr 30, 2025
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows...
Moderate
Unreviewed
CVE-2025-24343
was published
Apr 30, 2025
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Low
Unreviewed
CVE-2023-35816
was published
Apr 28, 2025
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was...
Moderate
Unreviewed
CVE-2025-46433
was published
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API