GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,190 advisories
Filter by severity
The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path...
High
Unreviewed
CVE-2025-41714
was published
Sep 10, 2025
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to...
High
Unreviewed
CVE-2025-23343
was published
Sep 9, 2025
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
High
CVE-2025-58755
was published
for
monai
(pip)
Sep 9, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability...
High
Unreviewed
CVE-2025-41035
was published
Sep 4, 2025
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-7975
was published
Sep 2, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an...
High
Unreviewed
CVE-2025-52861
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33037
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33033
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33036
was published
Aug 29, 2025
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker...
High
Unreviewed
CVE-2025-33038
was published
Aug 29, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an...
High
Unreviewed
CVE-2024-13986
was published
Aug 28, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54029
was published
Aug 28, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-53588
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-54819
was published
Aug 28, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
High
Unreviewed
CVE-2025-58072
was published
Aug 28, 2025
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON...
High
Unreviewed
CVE-2024-13982
was published
Aug 28, 2025
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to...
High
Unreviewed
CVE-2025-50971
was published
Aug 26, 2025
xml2rfc has an arbitrary file read vulnerability
High
CVE-2025-11058
was published
for
xml2rfc
(pip)
Aug 26, 2025
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
High
Unreviewed
CVE-2025-29420
was published
Aug 26, 2025
In MindManager Windows versions prior to 24.1.150, attackers could potentially write to...
High
Unreviewed
CVE-2024-56179
was published
Aug 22, 2025
Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall...
High
Unreviewed
CVE-2010-20109
was published
Aug 21, 2025
Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows...
High
Unreviewed
CVE-2012-10061
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API