GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
138 advisories
Filter by severity
Traefik has a possible vulnerability with the path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
go.rgst.io/stencil/v2 vulnerable to Path Traversal
Moderate
GHSA-p799-q2pr-6mxj
was published
for
go.rgst.io/stencil/v2
(Go)
Mar 29, 2025
github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Moderate
GHSA-j95m-rcjp-q69h
was published
for
github.com/jaredallard/archives
(Go)
Mar 28, 2025
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
OpenShift Console Has a Path Traversal Vulnerability
Moderate
CVE-2024-7631
was published
for
github.com/openshift/console
(Go)
Mar 19, 2025
Mattermost allows reading arbitrary files related to importing boards
Critical
CVE-2025-25279
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost allows reading arbitrary files
Critical
CVE-2025-20051
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
WhoDB has a path traversal opening Sqlite3 database
Critical
CVE-2025-24786
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
CRI-O Path Traversal vulnerability
Moderate
CVE-2025-0750
was published
for
github.com/cri-o/cri-o
(Go)
Jan 28, 2025
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
Karmada Tar Slips in CRDs archive extraction
Moderate
CVE-2024-56514
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
Path Traversal in file update API in gogs
High
CVE-2024-55947
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Remote Command Execution in file editing in gogs
High
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file write in the host via /api/asset/upload
High
CVE-2024-55659
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability
Moderate
CVE-2024-54132
was published
for
github.com/cli/cli
(Go)
Dec 4, 2024
Kubernetes kubelet arbitrary command execution
High
CVE-2024-10220
was published
for
k8s.io/kubernetes
(Go)
Nov 22, 2024
Unpatched Remote Code Execution in Gogs
High
CVE-2024-44625
was published
for
gogs.io/gogs
(Go)
Nov 15, 2024
Hashicorp Consul Path Traversal vulnerability
High
CVE-2024-10005
was published
for
github.com/hashicorp/consul
(Go)
Oct 31, 2024
Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.
Moderate
CVE-2024-47877
was published
for
github.com/codeclysm/extract
(Go)
Oct 11, 2024
Buildah allows arbitrary directory mount
Moderate
CVE-2024-9675
was published
for
github.com/containers/buildah
(Go)
Oct 9, 2024
Adguard Home arbitrary file read vulnerability
High
CVE-2024-36814
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Oct 8, 2024
Path traversal vulnerability in stripe-cli
Low
CVE-2024-45401
was published
for
github.com/stripe/stripe-cli
(Go)
Sep 5, 2024
ProTip!
Advisories are also available from the
GraphQL API