GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
364 advisories
Filter by severity
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
hashi-vault-js has a path traversal and query parameter injection
High
CVE-2026-55100
was published
for
hashi-vault-js
(npm)
Jul 31, 2026
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing...
High
Unreviewed
CVE-2026-18192
was published
Jul 29, 2026
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP...
Moderate
Unreviewed
CVE-2026-63303
was published
Jul 28, 2026
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2026-15802
was published
Jul 22, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-51026
was published
Jul 20, 2026
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code...
High
Unreviewed
CVE-2026-56196
was published
Jul 14, 2026
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate...
High
Unreviewed
CVE-2026-50454
was published
Jul 14, 2026
Relative path traversal in DNS Server allows an authorized attacker to execute code over an...
Moderate
Unreviewed
CVE-2026-50426
was published
Jul 14, 2026
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized...
High
Unreviewed
CVE-2026-50663
was published
Jul 14, 2026
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over...
High
Unreviewed
CVE-2026-40400
was published
Jul 14, 2026
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated...
High
Unreviewed
CVE-2026-14903
was published
Jul 14, 2026
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
High
CVE-2026-54066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project...
Critical
Unreviewed
CVE-2026-59792
was published
Jul 10, 2026
LibreBooking's email template editor save action passes the submitted template name directly into...
High
Unreviewed
CVE-2026-61343
was published
Jul 9, 2026
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).
This...
Moderate
Unreviewed
CVE-2026-8650
was published
Jul 8, 2026
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when ...
Moderate
Unreviewed
CVE-2026-59995
was published
Jul 8, 2026
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when...
Moderate
Unreviewed
CVE-2026-59996
was published
Jul 8, 2026
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components()...
High
Unreviewed
CVE-2026-14476
was published
Jul 7, 2026
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows...
High
Unreviewed
CVE-2026-57871
was published
Jul 7, 2026
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose...
Moderate
Unreviewed
CVE-2026-58522
was published
Jul 3, 2026
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to...
High
Unreviewed
CVE-2026-57988
was published
Jul 3, 2026
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38...
High
Unreviewed
CVE-2026-44941
was published
Jul 2, 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
High
CVE-2026-50181
was published
for
langroid
(pip)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API