GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,883
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,200
NuGet
743
pip
3,977
Pub
12
RubyGems
947
Rust
1,032
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,109 advisories
Filter by severity
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on...
Moderate
Unreviewed
CVE-2024-41887
was published
Dec 24, 2024
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8559
was published
Sep 30, 2025
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2024-2654
was published
Apr 9, 2024
A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function...
Moderate
Unreviewed
CVE-2025-11139
was published
Sep 29, 2025
A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element...
Moderate
Unreviewed
CVE-2025-11034
was published
Sep 26, 2025
A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2025-11031
was published
Sep 26, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects...
Moderate
Unreviewed
CVE-2025-11018
was published
Sep 26, 2025
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected...
Moderate
Unreviewed
CVE-2025-11016
was published
Sep 26, 2025
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-10307
was published
Sep 26, 2025
ml-logger has path traversal in the file argument
Moderate
CVE-2025-10951
was published
for
ml-logger
(pip)
Sep 25, 2025
An issue in the component /importmould/deletefolder of Weaver Ecology v9.* allows authenticated...
Moderate
Unreviewed
CVE-2024-48071
was published
Nov 19, 2024
A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the...
Moderate
Unreviewed
CVE-2023-41290
was published
Apr 26, 2024
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in...
Moderate
Unreviewed
CVE-2024-49421
was published
Dec 3, 2024
A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the...
Moderate
Unreviewed
CVE-2023-41291
was published
Apr 26, 2024
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2024-37043
was published
Nov 22, 2024
A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10777
was published
Sep 22, 2025
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10766
was published
Sep 22, 2025
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers...
Moderate
Unreviewed
CVE-2025-56869
was published
Sep 22, 2025
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to...
Moderate
Unreviewed
CVE-2025-57682
was published
Sep 22, 2025
A path traversal vulnerability has been reported to affect several QNAP operating system versions...
Moderate
Unreviewed
CVE-2025-33032
was published
Aug 29, 2025
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0....
Moderate
Unreviewed
CVE-2025-10709
was published
Sep 19, 2025
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization...
Moderate
Unreviewed
CVE-2025-10708
was published
Sep 19, 2025
ProTip!
Advisories are also available from the
GraphQL API