GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
124 advisories
Filter by severity
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File...
Moderate
Unreviewed
CVE-2025-4602
was published
May 24, 2025
Kea configuration and API directives can be used to overwrite arbitrary files, subject to...
Moderate
Unreviewed
CVE-2025-32802
was published
May 28, 2025
CloudLinux
CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to
the sendmail...
Moderate
Unreviewed
CVE-2020-36772
was published
Jan 22, 2024
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-47956
was published
Jun 10, 2025
OctoPrint vulnerable to possible file extraction via upload endpoints
Moderate
CVE-2025-48067
was published
for
OctoPrint
(pip)
Jun 10, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3...
Moderate
Unreviewed
CVE-2025-36506
was published
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
External control of file name or path in Windows Security App allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-53769
was published
Aug 12, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20269
was published
Aug 20, 2025
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element...
Moderate
Unreviewed
CVE-2025-9529
was published
Aug 27, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts...
Moderate
Unreviewed
CVE-2025-9920
was published
Sep 9, 2025
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-47265
was published
Feb 13, 2025
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4...
Moderate
Unreviewed
CVE-2024-22341
was published
Feb 22, 2025
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables...
Moderate
Unreviewed
CVE-2025-0124
was published
Apr 11, 2025
External control of file name or path in Windows Core Shell allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-59244
was published
Oct 14, 2025
External control of file name or path in Windows Core Shell allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-59185
was published
Oct 14, 2025
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all...
Moderate
Unreviewed
CVE-2025-11738
was published
Oct 18, 2025
NTLM Hash Disclosure Spoofing Vulnerability
Moderate
Unreviewed
CVE-2024-43451
was published
Nov 12, 2024
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal....
Moderate
Unreviewed
CVE-2025-8048
was published
Oct 20, 2025
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.
...
Moderate
Unreviewed
CVE-2025-8050
was published
Oct 21, 2025
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-12137
was published
Nov 1, 2025
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path...
Moderate
Unreviewed
CVE-2023-47171
was published
Jan 10, 2024
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image...
Moderate
Unreviewed
CVE-2023-49863
was published
Jan 10, 2024
ProTip!
Advisories are also available from the
GraphQL API