GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,300
NuGet
760
pip
4,078
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
132 advisories
Filter by severity
**UNSUPPORTED WHEN ASSIGNED** Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1...
Critical
Unreviewed
CVE-2024-40505
was published
Jul 16, 2024
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks,...
High
Unreviewed
CVE-2024-39171
was published
Jul 9, 2024
In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could...
High
Unreviewed
CVE-2024-36991
was published
Jul 1, 2024
htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the...
Moderate
Unreviewed
CVE-2024-34191
was published
May 14, 2024
The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to,...
Moderate
Unreviewed
CVE-2024-2654
was published
Apr 9, 2024
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of...
High
Unreviewed
CVE-2024-27901
was published
Apr 9, 2024
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG...
Moderate
Unreviewed
CVE-2024-2863
was published
Mar 25, 2024
: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability...
Moderate
Unreviewed
CVE-2023-41793
was published
Mar 19, 2024
This vulnerability allows remote attackers to traverse the directory on the affected webOS of...
Low
Unreviewed
CVE-2024-1886
was published
Feb 26, 2024
Vintage,
member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay...
Moderate
Unreviewed
CVE-2023-5800
was published
Feb 5, 2024
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an...
High
Unreviewed
CVE-2023-47279
was published
Dec 1, 2023
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an...
High
Unreviewed
CVE-2023-46690
was published
Dec 1, 2023
The discontinued FFS Colibri product allows a remote user to access files on the system including...
Moderate
Unreviewed
CVE-2023-5885
was published
Nov 28, 2023
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter....
High
Unreviewed
CVE-2023-6252
was published
Nov 22, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup...
High
Unreviewed
CVE-2023-21418
was published
Nov 21, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API...
High
Unreviewed
CVE-2023-21416
was published
Nov 21, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program,
has found that the VAPIX API...
High
Unreviewed
CVE-2023-21417
was published
Nov 21, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43803
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - local privilege escalation vulnerability
High
CVE-2023-43802
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43801
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del...
High
Unreviewed
CVE-2023-21415
was published
Oct 16, 2023
NLnet Labs’ Routinator vulnerable to path traversal
Critical
CVE-2023-39916
was published
for
routinator
(Rust)
Sep 13, 2023
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a...
High
Unreviewed
CVE-2023-32714
was published
Jun 1, 2023
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
High
Unreviewed
CVE-2022-48476
was published
Apr 24, 2023
The File Management System developed by FileOrbis before version 10.6.3 has an unauthenticated...
High
Unreviewed
CVE-2022-3693
was published
Jan 13, 2023
ProTip!
Advisories are also available from the
GraphQL API