GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
59 advisories
Filter by severity
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API ledlimit.cgi...
Moderate
Unreviewed
CVE-2024-0067
was published
Sep 10, 2024
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File...
High
Unreviewed
CVE-2024-51582
was published
Nov 4, 2024
Path traversal in oak allows transfer of hidden files within the served root directory
High
CVE-2024-49770
was published
for
@oakserver/oak
(npm)
Nov 1, 2024
Path Traversal: '.../...//' vulnerability in Limb WordPress Gallery Plugin – Limb Image Gallery...
Moderate
Unreviewed
CVE-2024-49258
was published
Oct 16, 2024
Multi-DNC – CWE-35: Path Traversal: '.../...//'
High
Unreviewed
CVE-2024-45248
was published
Oct 6, 2024
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support,...
High
Unreviewed
CVE-2024-0113
was published
Aug 12, 2024
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the...
Moderate
Unreviewed
CVE-2024-34191
was published
May 14, 2024
An authenticated user can download sensitive files from Trellix products NX, EX, FX, AX, IVX, ...
Moderate
Unreviewed
CVE-2024-7608
was published
Aug 27, 2024
Mage AI Path Traversal vulnerability
Moderate
CVE-2024-45190
was published
for
mage-ai
(pip)
Aug 23, 2024
**UNSUPPORTED WHEN ASSIGNED** Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1...
Critical
Unreviewed
CVE-2024-40505
was published
Jul 16, 2024
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could...
High
Unreviewed
CVE-2024-36991
was published
Jul 1, 2024
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks,...
High
Unreviewed
CVE-2024-39171
was published
Jul 9, 2024
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of...
High
Unreviewed
CVE-2024-27901
was published
Apr 9, 2024
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal...
Moderate
Unreviewed
CVE-2023-39916
was published
Sep 13, 2023
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a...
High
Unreviewed
CVE-2023-32714
was published
Jun 1, 2023
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
High
Unreviewed
CVE-2022-48476
was published
Apr 24, 2023
The discontinued FFS Colibri product allows a remote user to access files on the system including...
Moderate
Unreviewed
CVE-2023-5885
was published
Nov 28, 2023
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG...
Moderate
Unreviewed
CVE-2024-2863
was published
Mar 25, 2024
: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability...
Moderate
Unreviewed
CVE-2023-41793
was published
Mar 19, 2024
This vulnerability allows remote attackers to traverse the directory on the affected webOS of...
Low
Unreviewed
CVE-2024-1886
was published
Feb 26, 2024
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an...
High
Unreviewed
CVE-2023-47279
was published
Dec 1, 2023
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an...
High
Unreviewed
CVE-2023-46690
was published
Dec 1, 2023
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter....
High
Unreviewed
CVE-2023-6252
was published
Nov 22, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43803
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - local privilege escalation vulnerability
High
CVE-2023-43802
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
ProTip!
Advisories are also available from the
GraphQL API