GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
2,823 advisories
Filter by severity
Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component...
High
Unreviewed
CVE-2021-29088
was published
May 24, 2022
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2021-29087
was published
May 24, 2022
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and...
High
Unreviewed
CVE-2024-13158
was published
Jan 14, 2025
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker...
High
Unreviewed
CVE-2024-13181
was published
Jan 14, 2025
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker...
High
Unreviewed
CVE-2024-13180
was published
Jan 14, 2025
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker...
High
Unreviewed
CVE-2024-13179
was published
Jan 14, 2025
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console...
High
Unreviewed
CVE-2023-28344
was published
May 31, 2023
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet...
High
Unreviewed
CVE-2024-48884
was published
Jan 14, 2025
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet...
High
Unreviewed
CVE-2024-36512
was published
Jan 14, 2025
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules...
High
Unreviewed
CVE-2023-30196
was published
May 30, 2023
Spring Framework Path Traversal vulnerability
High
CVE-2024-38819
was published
for
org.springframework:spring-webflux
(Maven)
Dec 19, 2024
Hashicorp Consul Path Traversal vulnerability
High
CVE-2024-10005
was published
for
github.com/hashicorp/consul
(Go)
Oct 31, 2024
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up...
High
Unreviewed
CVE-2024-9939
was published
Jan 8, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-56286
was published
Jan 7, 2025
The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all...
High
Unreviewed
CVE-2024-12152
was published
Jan 7, 2025
The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all...
High
Unreviewed
CVE-2024-12849
was published
Jan 7, 2025
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules...
High
Unreviewed
CVE-2023-30198
was published
Jun 12, 2023
@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability
High
CVE-2024-45816
was published
for
@backstage/plugin-techdocs-backend
(npm)
Sep 17, 2024
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18,...
High
Unreviewed
CVE-2024-54453
was published
Dec 27, 2024
iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability...
High
Unreviewed
CVE-2024-11944
was published
Dec 30, 2024
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
High
CVE-2024-56509
was published
for
changedetection.io
(pip)
Dec 27, 2024
Path traversal vulnerability in functional web frameworks
High
CVE-2024-38816
was published
for
org.springframework:spring-webflux
(Maven)
Sep 13, 2024
Remote Command Execution in file editing in gogs
High
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a...
High
Unreviewed
CVE-2024-53961
was published
Dec 23, 2024
Path Traversal in file update API in gogs
High
CVE-2024-55947
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
ProTip!
Advisories are also available from the
GraphQL API