GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
126 advisories
Filter by severity
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An...
Low
Unreviewed
CVE-2022-37703
was published
Sep 14, 2022
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient...
Low
Unreviewed
CVE-2023-49058
was published
Dec 12, 2023
Duplicate Advisory: Node CLI Allows Arbitrary File Overwrite
Low
CVE-2016-1000021
was published
for
cli
(npm)
May 24, 2022
•
withdrawn
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified...
Low
Unreviewed
CVE-2018-25094
was published
Dec 3, 2023
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to...
Low
Unreviewed
CVE-2023-6160
was published
Nov 22, 2023
It was discovered that Kibana was not validating a user supplied path, which would load .pbf...
Low
Unreviewed
CVE-2021-22151
was published
Nov 22, 2023
A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as...
Low
Unreviewed
CVE-2023-5257
was published
Sep 29, 2023
sbt vulnerable to arbitrary file write via archive extraction (Zip Slip)
Low
CVE-2023-46122
was published
for
org.scala-sbt:io_2.12
(Maven)
Oct 24, 2023
Puppet vulnerable to Path Traversal
Low
CVE-2012-3865
was published
for
puppet
(RubyGems)
Oct 24, 2017
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR...
Low
Unreviewed
CVE-2023-5142
was published
Sep 25, 2023
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic....
Low
Unreviewed
CVE-2023-5327
was published
Oct 2, 2023
Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki
Low
GHSA-8459-6rc9-8vf8
was published
for
github.com/cloudflare/cfrpki
(Go)
Feb 14, 2022
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hyper-bump-it
Low
CVE-2023-41057
was published
for
hyper-bump-it
(pip)
Sep 4, 2023
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this...
Low
Unreviewed
CVE-2023-3241
was published
Jun 14, 2023
Cargo extracting malicious crates can corrupt arbitrary files
Low
CVE-2022-36113
was published
for
cargo
(Rust)
Sep 16, 2022
Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by...
Low
Unreviewed
CVE-2020-15858
was published
May 24, 2022
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access...
Low
Unreviewed
CVE-2023-21448
was published
Feb 9, 2023
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage...
Low
Unreviewed
CVE-2015-5313
was published
May 14, 2022
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running...
Low
Unreviewed
CVE-2011-3171
was published
May 17, 2022
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to...
Low
Unreviewed
CVE-2012-0991
was published
May 17, 2022
Directory traversal vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple ...
Low
Unreviewed
CVE-2012-6064
was published
May 17, 2022
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4...
Low
Unreviewed
CVE-2013-2978
was published
May 17, 2022
Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency...
Low
Unreviewed
CVE-2013-3004
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API