GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
93 advisories
Filter by severity
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal...
High
Unreviewed
CVE-2026-14947
was published
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold...
Moderate
Unreviewed
CVE-2026-76353
was published
Aug 20, 2026
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra...
Low
Unreviewed
CVE-2026-73573
was published
Aug 13, 2026
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and...
High
Unreviewed
CVE-2026-66140
was published
Jul 24, 2026
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
High
CVE-2026-34151
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 7, 2026
A path traversal in handling the "path" component of .repo files processed by libzypp before 17...
Moderate
Unreviewed
CVE-2026-44942
was published
Jun 18, 2026
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the...
Critical
Unreviewed
CVE-2026-49103
was published
May 27, 2026
XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
Moderate
CVE-2026-48047
was published
for
org.xwiki.platform:xwiki-platform-webjars-api
(Maven)
May 26, 2026
@joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files
High
CVE-2026-22810
was published
for
@joplin/onenote-converter
(npm)
May 15, 2026
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to...
High
Unreviewed
CVE-2026-41082
was published
Apr 16, 2026
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5,...
Critical
Unreviewed
CVE-2026-39813
was published
Apr 14, 2026
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
High
CVE-2026-40318
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 10, 2026
Fonoster is vulnerable to directory traversal
Moderate
CVE-2024-43035
was published
for
@fonoster/voice
(npm)
Mar 5, 2026
Path traversal vulnerability in the certificate management module. Impact: Successful...
Moderate
Unreviewed
CVE-2026-28538
was published
Mar 5, 2026
fast-filesystem-mcp has a Path Traversal vulnerability
High
CVE-2025-67364
was published
for
fast-filesystem-mcp
(npm)
Jan 7, 2026
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read
High
CVE-2026-21857
was published
for
redaxo/source
(Composer)
Jan 5, 2026
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform...
Moderate
Unreviewed
CVE-2025-67845
was published
Dec 19, 2025
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the...
Moderate
Unreviewed
CVE-2025-61318
was published
Dec 8, 2025
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes...
High
Unreviewed
CVE-2025-51661
was published
Nov 19, 2025
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1...
High
Unreviewed
CVE-2025-63298
was published
Oct 30, 2025
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25...
High
Unreviewed
CVE-2023-53691
was published
Oct 22, 2025
An unauthenticated Local File Inclusion (LFI) vulnerability in D-Link DSR series routers allows...
Moderate
Unreviewed
CVE-2025-60344
was published
Oct 21, 2025
A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read...
High
Unreviewed
CVE-2025-57618
was published
Oct 14, 2025
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows...
Moderate
Unreviewed
CVE-2025-57563
was published
Oct 14, 2025
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint...
Moderate
Unreviewed
CVE-2025-61189
was published
Oct 1, 2025
ProTip!
Advisories are also available from the
GraphQL API