GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
64 advisories
Filter by severity
An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6...
Critical
Unreviewed
CVE-2025-65473
was published
Dec 11, 2025
jsPDF has Local File Inclusion/Path Traversal vulnerability
Critical
CVE-2025-68428
was published
for
jspdf
(npm)
Jan 5, 2026
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS...
Critical
Unreviewed
CVE-2025-53912
was published
Jan 20, 2026
An external control of file name or path vulnerability in SUNNET Corporate Training Management...
Critical
Unreviewed
CVE-2025-54945
was published
Sep 25, 2025
H2O has an External Control of File Name or Path vulnerability
Critical
CVE-2024-5986
was published
for
ai.h2o:h2o-core
(Maven)
Feb 2, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Critical
CVE-2025-64712
was published
for
unstructured
(pip)
Feb 3, 2026
survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical
CVE-2026-25630
was published
for
survey-pdf
(npm)
Feb 4, 2026
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
Critical
GHSA-97m3-52wr-xvv2
was published
for
phenx/php-svg-lib
(Composer)
Feb 22, 2024
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite...
Critical
Unreviewed
CVE-2026-30281
was published
Mar 31, 2026
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers...
Critical
Unreviewed
CVE-2026-30276
was published
Mar 31, 2026
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2025-4603
was published
May 24, 2025
The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to...
Critical
Unreviewed
CVE-2025-2004
was published
Apr 8, 2025
External Control of File Name or Path in h2oai/h2o-3
Critical
CVE-2023-6569
was published
for
h2o
(pip)
Dec 14, 2023
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote...
Critical
Unreviewed
CVE-2026-8043
was published
May 12, 2026
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6...
Critical
Unreviewed
CVE-2026-30903
was published
Mar 11, 2026
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the...
Critical
Unreviewed
CVE-2026-47357
was published
May 19, 2026
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL...
Critical
Unreviewed
CVE-2026-47358
was published
May 19, 2026
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource...
Critical
Unreviewed
CVE-2024-9142
was published
Sep 25, 2024
Langflow has an Arbitrary File Write (RCE) via v2 API
Critical
CVE-2026-33309
was published
for
langflow
(pip)
Mar 19, 2026
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2026-39006
was published
Jun 15, 2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-47643
was published
Jun 9, 2026
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open()...
Critical
Unreviewed
CVE-2026-11526
was published
Jun 14, 2026
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access...
Critical
Unreviewed
CVE-2025-71334
was published
Jun 26, 2026
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process...
Critical
Unreviewed
CVE-2025-71338
was published
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API