GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
80 advisories
Filter by severity
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
High
Unreviewed
CVE-2025-60835
was published
Jul 22, 2026
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
High
Unreviewed
CVE-2026-52707
was published
Jun 17, 2026
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
High
Unreviewed
CVE-2026-49112
was published
Jun 15, 2026
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
High
Unreviewed
CVE-2026-42661
was published
Jun 15, 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2026-45495
was published
May 18, 2026
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently ...
High
Unreviewed
CVE-2026-44933
was published
May 20, 2026
The File Management System developed by FileOrbis before version 10.6.3 has an unauthenticated...
High
Unreviewed
CVE-2022-3693
was published
Jan 13, 2023
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before...
High
Unreviewed
CVE-2022-2265
was published
Sep 22, 2022
Rancher Extensions have arbitrary file access via path traversal
High
CVE-2026-25705
was published
for
github.com/rancher/rancher
(Go)
May 7, 2026
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may...
High
Unreviewed
CVE-2026-42930
was published
May 13, 2026
Heimdall has an authorization bypass via path normalization mismatch
High
CVE-2026-42274
was published
for
github.com/dadrus/heimdall
(Go)
Apr 25, 2026
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an...
High
Unreviewed
CVE-2026-20034
was published
May 6, 2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-49405
was published
Aug 28, 2025
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue...
High
Unreviewed
CVE-2024-56055
was published
Dec 18, 2024
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue...
High
Unreviewed
CVE-2024-56049
was published
Dec 18, 2024
Path Traversal: '.../...//' vulnerability in Corporate Zen Contact Page With Google Map allows...
High
Unreviewed
CVE-2024-52447
was published
Nov 20, 2024
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File...
High
Unreviewed
CVE-2024-51582
was published
Nov 4, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2024-47324
was published
Oct 5, 2024
Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file...
High
Unreviewed
CVE-2026-25397
was published
Mar 25, 2026
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-47176
was published
Jun 10, 2025
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
High
Unreviewed
CVE-2025-64676
was published
Dec 19, 2025
The Access Manager is using the open source web server CompactWebServer written in C#. This web...
High
Unreviewed
CVE-2025-59099
was published
Jan 26, 2026
Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This...
High
Unreviewed
CVE-2025-67914
was published
Jan 8, 2026
Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner...
High
Unreviewed
CVE-2025-58972
was published
Nov 6, 2025
Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka...
High
Unreviewed
CVE-2025-48090
was published
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API