GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
7,289 advisories
Filter by severity
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not...
Moderate
Unreviewed
CVE-2025-34176
was published
Sep 9, 2025
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this...
Moderate
Unreviewed
CVE-2025-11914
was published
Oct 17, 2025
A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by...
Moderate
Unreviewed
CVE-2025-11913
was published
Oct 17, 2025
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory...
High
Unreviewed
CVE-2022-37060
was published
Aug 19, 2022
A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read...
Critical
Unreviewed
CVE-2025-62353
was published
Oct 17, 2025
A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to...
High
Unreviewed
CVE-2025-62356
was published
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
Smidge is vulnerable to Path Traversal
Moderate
CVE-2025-11842
was published
for
Smidge
(NuGet)
Oct 16, 2025
Mautic allows Relative Path Traversal in assets file upload
Moderate
CVE-2022-25773
was published
for
mautic/core
(Composer)
Feb 26, 2025
PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
Moderate
CVE-2025-61923
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component:...
Critical
Unreviewed
CVE-2025-61882
was published
Oct 5, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal...
High
Unreviewed
CVE-2025-34517
was published
Oct 16, 2025
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal...
High
Unreviewed
CVE-2025-34518
was published
Oct 16, 2025
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime...
High
Unreviewed
CVE-2025-61884
was published
Oct 12, 2025
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability ...
Moderate
Unreviewed
CVE-2025-53951
was published
Oct 16, 2025
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability ...
High
Unreviewed
CVE-2025-54658
was published
Oct 16, 2025
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled...
High
Unreviewed
CVE-2025-8941
was published
Aug 13, 2025
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
High
CVE-2024-8060
was published
for
open-webui
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical
CVE-2024-10902
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
LoLLMS vulnerable to Expected Behavior Violation
High
CVE-2024-6281
was published
for
lollms
(pip)
Jul 20, 2024
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Critical
CVE-2024-5980
was published
for
lightning
(pip)
Jun 27, 2024
ProTip!
Advisories are also available from the
GraphQL API