GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      106 advisories
        Filter by severity
        
      
      
    
                    
                      Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-12425
                      
                      was published
                      Jan 7, 2025 
                    
                  
                    
                      IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2013-3993
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      A path traversal vulnerability has been reported to affect several QNAP operating system versions...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-37046
                      
                      was published
                      Nov 22, 2024 
                    
                  
                    
                      An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55523
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8522
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed  an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3722
                      
                      was published
                      Jun 26, 2025 
                    
                  
                    
                      A path handling issue was addressed with improved validation. This issue is fixed in macOS...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-40383
                      
                      was published
                      Jan 11, 2024 
                    
                  
                    
                      A vulnerability in the web-based management interface of Cisco Unified CCX could allow an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20277
                      
                      was published
                      Jun 4, 2025 
                    
                  
                    
                      The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-2252
                      
                      was published
                      Jan 16, 2024 
                    
                  
                    
                      In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-24940
                      
                      was published
                      Feb 6, 2024 
                    
                  
                    
                      Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-22479
                      
                      was published
                      May 6, 2025 
                    
                  
                    
                      The Permission Model assumes that any path starting with two backslashes \ has a four-character...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-37372
                      
                      was published
                      Jan 9, 2025 
                    
                  
                    
                      The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32943
                      
                      was published
                      Apr 15, 2025 
                    
                  
                    
                      Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-8737
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-9461
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2012-3380
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2010-0926
                      
                      was published
                      May 2, 2022 
                    
                  
                    
                      Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32205
                      
                      was published
                      Apr 10, 2025 
                    
                  
                    
                      unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with "....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2006-0950
                      
                      was published
                      May 1, 2022 
                    
                  
                    
                      Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27726
                      
                      was published
                      Mar 28, 2025 
                    
                  
                    
                      A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30343
                      
                      was published
                      Mar 21, 2025 
                    
                  
                    
                      A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41511
                      
                      was published
                      Oct 4, 2024 
                    
                  
                    
                      Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-40160
                      
                      was published
                      Mar 18, 2024 
                    
                  
                    
                      In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0526
                      
                      was published
                      Feb 11, 2025 
                    
                  
                    
                      A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal,...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-34521
                      
                      was published
                      Feb 13, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API