GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,883
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,200
NuGet
743
pip
3,977
Pub
12
RubyGems
947
Rust
1,032
Swift
39
Unreviewed advisories
All unreviewed
5,000+
7,224 advisories
Filter by severity
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to...
High
Unreviewed
CVE-2025-59744
was published
Oct 2, 2025
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL...
High
Unreviewed
CVE-2025-11020
was published
Oct 2, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code...
High
Unreviewed
CVE-2025-11182
was published
Oct 2, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted...
Critical
Unreviewed
CVE-2025-11221
was published
Oct 2, 2025
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
Low
CVE-2025-58769
was published
for
auth0/auth0-php
(Composer)
Oct 1, 2025
The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions...
Moderate
Unreviewed
CVE-2025-8559
was published
Sep 30, 2025
Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet
Moderate
CVE-2025-43813
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 30, 2025
A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function...
Moderate
Unreviewed
CVE-2025-11139
was published
Sep 29, 2025
A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element...
Moderate
Unreviewed
CVE-2025-11034
was published
Sep 26, 2025
A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of...
Moderate
Unreviewed
CVE-2025-11031
was published
Sep 26, 2025
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected...
Moderate
Unreviewed
CVE-2025-11016
was published
Sep 26, 2025
A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects...
Moderate
Unreviewed
CVE-2025-11018
was published
Sep 26, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-59002
was published
Sep 26, 2025
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-10307
was published
Sep 26, 2025
ml-logger has path traversal in the file argument
Moderate
CVE-2025-10951
was published
for
ml-logger
(pip)
Sep 25, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-10449
was published
Sep 25, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the...
High
Unreviewed
CVE-2025-56816
was published
Sep 24, 2025
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since...
High
Unreviewed
CVE-2025-56815
was published
Sep 24, 2025
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and...
Critical
Unreviewed
CVE-2025-9963
was published
Sep 23, 2025
A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10777
was published
Sep 22, 2025
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function...
Moderate
Unreviewed
CVE-2025-10766
was published
Sep 22, 2025
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers...
Moderate
Unreviewed
CVE-2025-56869
was published
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API