GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
124 advisories
Filter by severity
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image...
Moderate
Unreviewed
CVE-2023-49862
was published
Jan 10, 2024
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image...
Moderate
Unreviewed
CVE-2023-49864
was published
Jan 10, 2024
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0...
Moderate
Unreviewed
CVE-2025-20614
was published
Nov 11, 2025
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control...
Moderate
Unreviewed
CVE-2022-4983
was published
Nov 13, 2025
External control of file name or path in certain Zoom Clients may allow an unauthenticated user...
Moderate
Unreviewed
CVE-2025-64739
was published
Nov 13, 2025
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow...
Moderate
Unreviewed
CVE-2025-64738
was published
Nov 13, 2025
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and...
Moderate
Unreviewed
CVE-2025-11973
was published
Nov 21, 2025
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-13380
was published
Nov 25, 2025
OpenStack's Mistral Client has a local file inclusion vulnerability
Moderate
CVE-2021-4472
was published
for
python-mistralclient
(pip)
Nov 26, 2025
External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an...
Moderate
Unreviewed
CVE-2025-67461
was published
Dec 10, 2025
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions...
Moderate
Unreviewed
CVE-2025-13320
was published
Dec 12, 2025
memos lacks file name validation or verification
Moderate
CVE-2025-65799
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all...
Moderate
Unreviewed
CVE-2025-14059
was published
Jan 7, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2026-20872
was published
Jan 13, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2026-20925
was published
Jan 13, 2026
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an...
Moderate
Unreviewed
CVE-2025-0105
was published
Jan 11, 2025
LobeHub Vulnerable to Improper Authorization in Presigned Upload
Moderate
CVE-2026-23835
was published
for
@lobehub/chat
(npm)
Feb 1, 2026
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform...
Moderate
Unreviewed
CVE-2025-24054
was published
Mar 11, 2025
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path...
Moderate
Unreviewed
CVE-2026-26361
was published
Feb 19, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
registry-support: decompress can delete files outside scope via relative paths
Moderate
CVE-2024-1485
was published
for
github.com/devfile/registry-support/registry-library
(Go)
Feb 14, 2024
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected...
Moderate
Unreviewed
CVE-2026-25605
was published
Mar 10, 2026
An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95...
Moderate
Unreviewed
CVE-2025-69621
was published
Feb 4, 2026
ProTip!
Advisories are also available from the
GraphQL API