GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,201
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,702
NuGet
660
pip
3,328
Pub
11
RubyGems
883
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,739 advisories
Filter by severity
Directory Traversal in citypredict.whauwiller
High
CVE-2017-16104
was published
for
citypredict.whauwiller
(npm)
Jul 24, 2018
Directory traversal in pooledwebsocket
High
CVE-2017-16107
was published
for
pooledwebsocket
(npm)
Jul 24, 2018
Directory Traversal in list-n-stream
High
CVE-2017-16084
was published
for
list-n-stream
(npm)
Jul 24, 2018
Directory Traversal in tinyserver2
High
CVE-2017-16085
was published
for
tinyserver2
(npm)
Jul 24, 2018
Directory Traversal in badjs-sourcemap-server
High
CVE-2017-16036
was published
for
badjs-sourcemap-server
(npm)
Jul 24, 2018
Directory Traversal in gomeplus-h5-proxy
High
CVE-2017-16037
was published
for
gomeplus-h5-proxy
(npm)
Jul 24, 2018
Directory Traversal in f2e-server
High
CVE-2017-16038
was published
for
f2e-server
(npm)
Jul 24, 2018
Directory Traversal in node-simple-router
High
CVE-2017-16083
was published
for
node-simple-router
(npm)
Jul 24, 2018
Path Traversal in localhost-now
High
CVE-2018-3729
was published
for
localhost-now
(npm)
Jul 25, 2018
Path Traversal in general-file-server
High
CVE-2018-3724
was published
for
general-file-server
(npm)
Jul 26, 2018
simplehttpserver allows directory traversal and file listing
High
CVE-2018-3787
was published
for
simplehttpserver
(npm)
Sep 6, 2018
Spark allows remote attackers to read arbitrary files via a .. (dot dot) in the URI
High
CVE-2016-9177
was published
for
com.sparkjava:spark-core
(Maven)
Oct 4, 2018
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
High
CVE-2016-9878
was published
for
org.springframework:spring-webmvc
(Maven)
Oct 4, 2018
High severity vulnerability that affects DotNetZip
High
CVE-2018-1002205
was published
for
DotNetZip
(NuGet)
Oct 16, 2018
In blynk-server a Directory Traversal exists
High
CVE-2018-17785
was published
for
com.github.blynkkk:blynk-server
(Maven)
Oct 17, 2018
Unzip function in ZipUtil.java in Hutool allows remote attackers to overwrite arbitrary files via directory traversal
High
CVE-2018-17297
was published
for
cn.hutool:hutool-all
(Maven)
Oct 17, 2018
ProTip!
Advisories are also available from the
GraphQL API