GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,319 advisories
Filter by severity
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since...
High
Unreviewed
CVE-2025-56815
was published
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the...
High
Unreviewed
CVE-2025-56816
was published
Sep 24, 2025
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and...
Critical
Unreviewed
CVE-2025-9963
was published
Sep 23, 2025
A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10777
was published
Sep 22, 2025
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10766
was published
Sep 22, 2025
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers...
Moderate
Unreviewed
CVE-2025-56869
was published
Sep 22, 2025
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to...
Moderate
Unreviewed
CVE-2025-57682
was published
Sep 22, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization...
Moderate
Unreviewed
CVE-2025-10708
was published
Sep 19, 2025
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0....
Moderate
Unreviewed
CVE-2025-10709
was published
Sep 19, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-10468
was published
Sep 19, 2025
InvokeAI has External Control of File Name or Path
Critical
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote...
Critical
Unreviewed
CVE-2025-59304
was published
Sep 17, 2025
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral'...
Moderate
Unreviewed
CVE-2025-35430
was published
Sep 17, 2025
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates,...
Moderate
Unreviewed
CVE-2025-9215
was published
Sep 17, 2025
The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File...
Moderate
Unreviewed
CVE-2025-10050
was published
Sep 17, 2025
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure...
High
Unreviewed
CVE-2025-34185
was published
Sep 16, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Moderate
Unreviewed
CVE-2025-43314
was published
Sep 16, 2025
A parsing issue in the handling of directory paths was addressed with improved path validation....
Moderate
Unreviewed
CVE-2025-43190
was published
Sep 16, 2025
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element...
Moderate
Unreviewed
CVE-2025-10472
was published
Sep 15, 2025
Flowise has arbitrary file access due to missing chat flow id validation
Critical
GHSA-q67q-549q-p849
was published
for
flowise
(npm)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API