GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,236 advisories
Filter by severity
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In...
High
Unreviewed
CVE-2025-65897
was published
Dec 5, 2025
The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The...
High
Unreviewed
CVE-2025-65878
was published
Dec 5, 2025
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability....
High
Unreviewed
CVE-2025-65879
was published
Dec 5, 2025
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The ...
High
Unreviewed
CVE-2025-54307
was published
Dec 4, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on...
High
Unreviewed
CVE-2025-64057
was published
Dec 5, 2025
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9...
High
Unreviewed
CVE-2025-22167
was published
Oct 22, 2025
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and...
High
Unreviewed
CVE-2025-39664
was published
Oct 9, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-54160
was published
Dec 4, 2025
A vulnerability in portenable cgi allows remote authenticated users to get the status of...
High
Unreviewed
CVE-2025-29846
was published
Dec 4, 2025
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
High
Unreviewed
CVE-2025-65838
was published
Dec 1, 2025
Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S...
High
Unreviewed
CVE-2025-66251
was published
Nov 26, 2025
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2025-13645
was published
Dec 3, 2025
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
High
CVE-2025-66295
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Gin-vue-admin has an arbitrary file deletion vulnerability
High
CVE-2025-66410
was published
for
github.com/flipped-aurora/gin-vue-admin
(Go)
Dec 2, 2025
Keras Directory Traversal Vulnerability
High
CVE-2025-12060
was published
for
keras
(pip)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
GHSA-28jp-44vh-q42h
was published
for
keras
(pip)
Oct 30, 2025
•
withdrawn
Grav is vulnerable to Arbitrary File Read
High
CVE-2025-66300
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12638
was published
for
Keras
(pip)
Nov 28, 2025
•
withdrawn
SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides...
High
Unreviewed
CVE-2025-63365
was published
Dec 1, 2025
Improper input sanitization in the file archives upload functionality of Eaton Galileo software...
High
Unreviewed
CVE-2025-59890
was published
Nov 27, 2025
Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Execution
High
CVE-2025-54386
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 1, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
esm.sh CDN service has arbitrary file write via tarslip
High
CVE-2025-65025
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
ProTip!
Advisories are also available from the
GraphQL API