GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
684 advisories
Filter by severity
PaddlePaddle Path Traversal vulnerability
Critical
CVE-2024-0818
was published
for
paddlepaddle
(pip)
Mar 7, 2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory...
Critical
Unreviewed
CVE-2024-25830
was published
Feb 29, 2024
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to...
Critical
Unreviewed
CVE-2024-25065
was published
Feb 29, 2024
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal...
Critical
Unreviewed
CVE-2024-23476
was published
Feb 15, 2024
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal...
Critical
Unreviewed
CVE-2024-23479
was published
Feb 15, 2024
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File...
Critical
Unreviewed
CVE-2024-26261
was published
Feb 15, 2024
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42...
Critical
Unreviewed
CVE-2023-40266
was published
Feb 9, 2024
Stimulsoft Dashboard.JS directory traversal vulnerability
Critical
CVE-2024-24398
was published
for
stimulsoft-dashboards-js
(npm)
Feb 6, 2024
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2024-0221
was published
Feb 6, 2024
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is...
Critical
Unreviewed
CVE-2023-6989
was published
Feb 6, 2024
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB,...
Critical
Unreviewed
CVE-2023-7077
was published
Feb 5, 2024
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
Critical
Unreviewed
CVE-2024-24482
was published
Feb 2, 2024
BuildKit vulnerable to possible host system access from mount stub cleaner
Critical
CVE-2024-23652
was published
for
github.com/moby/buildkit
(Go)
Jan 31, 2024
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature
Critical
CVE-2024-23827
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Jan 29, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16...
Critical
Unreviewed
CVE-2024-0402
was published
Jan 26, 2024
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
Critical
CVE-2024-23897
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jan 24, 2024
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers...
Critical
Unreviewed
CVE-2023-6623
was published
Jan 15, 2024
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory...
Critical
Unreviewed
CVE-2023-6699
was published
Jan 11, 2024
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
Critical
CVE-2023-49569
was published
for
github.com/go-git/go-git/v4
(Go)
Jan 10, 2024
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine...
Critical
Unreviewed
CVE-2023-47211
was published
Jan 8, 2024
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via...
Critical
Unreviewed
CVE-2023-5991
was published
Dec 26, 2023
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182
Critical
CVE-2023-50731
was published
for
mindsdb
(pip)
Dec 15, 2023
PHPMemcachedAdmin Path Traversal vulnerability
Critical
CVE-2023-6026
was published
for
elijaa/phpmemcacheadmin
(Composer)
Nov 30, 2023
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template...
Critical
Unreviewed
CVE-2023-46886
was published
Nov 29, 2023
ProTip!
Advisories are also available from the
GraphQL API